Branded Kernel CVEs — 2026-07-19

18 min read Original article ↗
CVE-2026-64164btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()SnoozeButterFShttps://snoozebutterfs.zip CVE-2026-64173tracing: Do not call map->ops->elt_free() if elt_alloc() failsPhantomFreehttps://phantomfree.lol CVE-2026-64172KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)IPIFreelyhttps://ipifreely.dog CVE-2026-64171i2c: tegra: fix pm_runtime leak on mutex_lock failureSleeplessInTegrahttps://sleeplessintegra.day CVE-2026-64170spi: qup: fix error pointer deref after DMA setup failureSpiKidshttps://spikids.film CVE-2026-64169spi: ep93xx: fix error pointer deref after DMA setup failureSpiGamehttps://spigame.stream CVE-2026-64168spi: sprd: fix error pointer deref after DMA setup failureSpiVsSpihttps://spivsspi.gg CVE-2026-64167kho: skip KHO for crash kernelKhoLateralhttps://kholateral.fail CVE-2026-64186iommu/amd: Remove latent out-of-bounds access in IOMMU debugfsIommOopshttps://iommoops.wtf CVE-2026-64185sysfs: don't remove existing directory on update failureDirNoMorehttps://dirnomore.rip CVE-2026-64184mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()DAMONSpawnhttps://damonspawn.horse CVE-2026-64166firmware: arm_ffa: Check for NULL FF-A ID table while driver registrationFFAndLoathinghttps://ffandloathing.film CVE-2026-64183efi: Allocate runtime workqueue before ACPI initEFIBirdhttps://efibird.aero CVE-2026-64182drivers/base/memory: fix memory block reference leak in poison accountingPoisonAccountanthttps://poisonaccountant.money CVE-2026-64181mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special()AbnormalPagehttps://abnormalpage.page CVE-2026-64180mm/memory_hotplug: fix memory block reference leak on removeHotUnpluggedhttps://hotunplugged.fm CVE-2026-64179net: wwan: iosm: fix potential memory leaks in ipc_imem_init()WWANtedhttps://wwanted.us CVE-2026-64178Bluetooth: bnep: Fix UAF read of dev->nameNameDropperhttps://namedropper.chat CVE-2026-64177phonet/pep: disable BH around forwarded sk_receive_skb()PepRallyhttps://peprally.party CVE-2026-64176wifi: iwlwifi: mvm: fix driver-set TX rates on old devicesRateExpectationshttps://rateexpectations.news CVE-2026-64175wifi: iwlwifi: mld: stop TX during firmware restartTXInterruptedhttps://txinterrupted.film CVE-2026-64174wifi: cfg80211: advance loop vars in cfg80211_merge_profile()ProfileSpinnerhttps://profilespinner.dj CVE-2026-64165ARM: integrator: Fix early initializationDisIntegratorhttps://disintegrator.energy CVE-2026-64123net: hsr: defer node table free until after RCU readersHSRDerailedhttps://hsrderailed.fail CVE-2026-64132ipv6: ioam: refresh hdr pointer before ioam6_event()IOAMnesiahttps://ioamnesia.wtf CVE-2026-64131mm/memory: fix spurious warning when unmapping device-private/exclusive pagesWarnOuthttps://warnout.rest CVE-2026-64130mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_freeZeroFolioGivenhttps://zerofoliogiven.lol CVE-2026-64129mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_pageSpinCityhttps://spincity.tv CVE-2026-64128Bluetooth: ISO: drop ISO_END frames received without prior ISO_STARTISOEndGamehttps://isoendgame.gg CVE-2026-64163test_kprobes: clear kprobes between test runsLingeringProbehttps://lingeringprobe.exposed CVE-2026-64127Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointerStackOverSharehttps://stackovershare.dev CVE-2026-64162idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()ClockBlockedhttps://clockblocked.watch CVE-2026-64161net: ti: icssm-prueth: fix eth_ports_node leak in probePortAuthorityhttps://portauthority.nyc CVE-2026-64160netfs: Fix potential for tearing in ->remote_i_size and ->zero_pointTearJerkerhttps://tearjerker.stream CVE-2026-64159netfs: Fix zeropoint update where i_size > remote_i_sizeZeroPointBreakhttps://zeropointbreak.surf CVE-2026-64158netfs: Fix write streaming disablement if fd open O_RDWRReadWriteWronghttps://readwritewrong.school CVE-2026-64157netfs: Fix partial invalidation of streaming-write folioHalfBakedFoliohttps://halfbakedfolio.pizza CVE-2026-64156netfs, afs: Fix write skipping in dir/link writepagesSkippedWriteDayhttps://skippedwriteday.fit CVE-2026-64155wifi: ath11k: fix error path leaks in some WMI WOW callsWorldOfLeakcrafthttps://worldofleakcraft.gg CVE-2026-64154drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()AdrenalineLeakhttps://adrenalineleak.energy CVE-2026-64153drm/msm: Fix iommu_map_sgtable() return value check and avoid WARNSGTableFliphttps://sgtableflip.rocks CVE-2026-64126Bluetooth: MGMT: validate Add Extended Advertising Data lengthTruthInAdvertisinghttps://truthinadvertising.biz CVE-2026-64152iommu: Handle unmap error when iommu_debug is enabledUnmapQuesthttps://unmapquest.lol CVE-2026-64151iommupt: Check for missing PAGE_SIZE in the pgsize_bitmapOneSizeFitsNonehttps://onesizefitsnone.fit CVE-2026-64150netfilter: nft_inner: release local_lock before re-enabling softirqsInnerTurmoilhttps://innerturmoil.art CVE-2026-64149dma-mapping: move dma_map_resource() sanity check into debug codeSanityOptionalhttps://sanityoptional.wtf CVE-2026-64148pds_core: fix error handling in pdsc_devcmd_waitCmdAndConquerhttps://cmdandconquer.io CVE-2026-64147pds_core: fix debugfs_lookup dentry leak and error handlingDentryPlanhttps://dentryplan.dental CVE-2026-64146erofs: fix metabuf leak in inode xattr initializationMetaBuffethttps://metabuffet.cafe CVE-2026-64145wifi: wilc1000: fix dma_buffer leak on bus acquire failureUnderTheBushttps://underthebus.taxi CVE-2026-64144Bluetooth: btmtk: fix urb->setup_packet leak in error pathsURBanLegendhttps://urbanlegend.fm CVE-2026-64143platform/x86: uniwill-laptop: Do not enable the charging limit even when forcedFullChargeAheadhttps://fullchargeahead.energy CVE-2026-64125net: bcmgenet: keep RBUF EEE/PM disabledEEEGadshttps://eeegads.lol CVE-2026-64142ksmbd: close durable scavenger races against m_fp_list lookupsScavengerHunthttps://scavengerhunt.party CVE-2026-64141ksmbd: fix null pointer dereference in compare_guid_key()MisGUIDedhttps://misguided.rip CVE-2026-64140ksmbd: fix null pointer dereference in proc_show_files()NothingToShowhttps://nothingtoshow.tv CVE-2026-64139ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflowSIDShowBobhttps://sidshowbob.tv CVE-2026-64138ksmbd: validate SID in parent security descriptor during ACL inheritanceInheritanceScamhttps://inheritancescam.money CVE-2026-64137smb: client: require net admin for CIFS SWN netlinkSwornWitnesshttps://swornwitness.lawyer CVE-2026-64136smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()TconArtisthttps://tconartist.biz CVE-2026-64135hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAXBlackBoxBlueshttps://blackboxblues.fm CVE-2026-64134ALSA: pcm: Don't setup bogus iov_iter for silencingSoundOfSilencehttps://soundofsilence.audio CVE-2026-64133ALSA: asihpi: Fix potential OOB array access at reading cacheCacheTwentyTwohttps://cachetwentytwo.aero CVE-2026-64124net: devmem: reject dma-buf bind with non-page-aligned size or SG lengthChaoticMisalignedhttps://chaoticmisaligned.games CVE-2026-64084hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NRPDIOverboardhttps://pdioverboard.cruises CVE-2026-64093batman-adv: tp_meter: directly shut down timer on cleanupSameBatTimehttps://samebattime.day CVE-2026-64092batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdownBatSignalLeakhttps://batsignalleak.news CVE-2026-64091batman-adv: tt: fix TOCTOU race for reported vlansVLANdalismhttps://vlandalism.art CVE-2026-64090batman-adv: tt: avoid empty VLAN responsesVLANishingActhttps://vlanishingact.show CVE-2026-64089batman-adv: tt: fix negative last_changeset_lenChangesetOfHearthttps://changesetofheart.chat CVE-2026-64088batman-adv: tt: fix negative tt_buff_lenNegativeBuffhttps://negativebuff.gg CVE-2026-64122net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recoverGhostReporterhttps://ghostreporter.news CVE-2026-64121net: ifb: report ethtool stats over num_tx_queuesStatPaddinghttps://statpadding.fit CVE-2026-64120net: ethtool: fix NULL pointer dereference in phy_reply_sizePHYnalAnswerhttps://phynalanswer.money CVE-2026-64119l2tp: use list_del_rcu in l2tp_session_unhashUnhashBrownshttps://unhashbrowns.kitchen CVE-2026-64118qed: fix double free in qed_cxt_tables_alloc()DoubleFreeDiscounthttps://doublefreediscount.deals CVE-2026-64117wifi: mac80211: capture fast-RX rate before mesh reuses skb->cbMeshedUphttps://meshedup.wtf CVE-2026-64116ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()HopSkipCrashhttps://hopskipcrash.horse CVE-2026-64115vsock/vmci: fix UAF when peer resets connection during handshakeHandshakeAndBakehttps://handshakeandbake.pizza CVE-2026-64114ipv4: raw: reject IP_HDRINCL packets with ihl < 5ShrunkenHeaderhttps://shrunkenheader.clothing CVE-2026-64087hwmon: (pmbus/adm1266) reject implausible blackbox record_countRecordScratchhttps://recordscratch.dj CVE-2026-64113ixgbevf: fix use-after-free in VEPA multicast source pruningPrunedToDeathhttps://prunedtodeath.garden CVE-2026-64112rbd: eliminate a race in lock_dwork draining on unmapDrainedAndConfusedhttps://drainedandconfused.plumbing CVE-2026-64111lsm: hold cred_guard_mutex for lsm_set_self_attr()SelfAttrEsteemhttps://selfattresteem.chat CVE-2026-64110igc: fix potential skb leak in igc_fpe_xmit_smd_frame()FramedAndLeakedhttps://framedandleaked.art CVE-2026-64109af_unix: Fix UAF read of tail->len in unix_stream_data_wait()TailRiskhttps://tailrisk.money CVE-2026-64108cifs: Fix busy dentry used after unmountingSquattersRightshttps://squattersrights.estate CVE-2026-64107ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put()OverclockAndDaggerhttps://overclockanddagger.dj CVE-2026-64106KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bitsEventIDHorizonhttps://eventidhorizon.events CVE-2026-64105KVM: arm64: vgic: Free private_irqs when init fails after allocationPrivateIRQuiryhttps://privateirquiry.agency CVE-2026-64104virt: sev-guest: Explicitly leak pages in unknown stateUnknownUnknownshttps://unknownunknowns.vote CVE-2026-64086hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read bufferPECSAppealhttps://pecsappeal.fit CVE-2026-64103scsi: isci: Fix use-after-free in device removal pathEvictionNoticehttps://evictionnotice.rent CVE-2026-64102RDMA/siw: Reject MPA FPDU length underflow before signed receive mathNegativeReceptionhttps://negativereception.reviews CVE-2026-64101fwctl: pds: Validate RPC input size before parsingSightUnseenhttps://sightunseen.auction CVE-2026-64100drm/msm: Fix shrinker deadlockShrinkStalematehttps://shrinkstalemate.care CVE-2026-64099drm/v3d: Fix use-after-free of CPU job query arrays on error pathQueriousGeorgehttps://queriousgeorge.tv CVE-2026-64098drm/virtio: use uninterruptible resv lock for plane updatesPlaneLockedhttps://planelocked.aero CVE-2026-64097drm/amd/display: Validate GPIO pin LUT table size before iteratingLUTOfTroublehttps://lutoftrouble.lol CVE-2026-64096batman-adv: mcast: fix use-after-free in orig_node RCU releaseOriginStoryhttps://originstory.film CVE-2026-64095batman-adv: bla: avoid double decrement of bla.num_requestsDecrementalHealthhttps://decrementalhealth.clinic CVE-2026-64094batman-adv: bla: avoid NULL-ptr deref for claim via dropped interfaceClaimDeniedhttps://claimdenied.claims CVE-2026-64085hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized bufferBlackboxBouncerhttps://blackboxbouncer.club CVE-2026-64045ovpn: tcp - use cached peer pointer in ovpn_tcp_close()PeerPressurehttps://peerpressure.school CVE-2026-64054net: shaper: reject duplicate leaves in GROUP requestLeafMeAlonehttps://leafmealone.garden CVE-2026-64053block: don't overwrite bip_vcnt in bio_integrity_copy_user()CheckBouncedhttps://checkbounced.cash CVE-2026-64052block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()ZeroIntegrityhttps://zerointegrity.vote CVE-2026-64051accel/qaic: Add overflow check to remap_pfn_range during mmapRemapRodeohttps://remaprodeo.horse CVE-2026-64050drm/msm/dpu: don't mix devm and drmm functionsDevmMayCarehttps://devmmaycare.wtf CVE-2026-64049drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xxAdrenoLinehttps://adrenoline.energy CVE-2026-64083hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessorsShortBushttps://shortbus.fail CVE-2026-64082riscv: Fix register corruption from uninitialized cregs on errorCregsListhttps://cregslist.biz CVE-2026-64081firmware: arm_ffa: Validate framework notification message layoutFFAkeNewshttps://ffakenews.news CVE-2026-64080firmware: arm_ffa: Snapshot notifier callbacks under lockSnapJudgmenthttps://snapjudgment.photos CVE-2026-64079netfilter: x_tables: allocate hook ops while under mutexHookedOnMutexhttps://hookedonmutex.rocks CVE-2026-64078netfilter: x_tables: add and use xtables_unregister_table_exitTableFliphttps://tableflip.furniture CVE-2026-64077netfilter: ebtables: move to two-stage removal schemeDoubleTakedownhttps://doubletakedown.lawyer CVE-2026-64076netfilter: bridge: eb_tables: close module init raceBridgeTooFasthttps://bridgetoofast.horse CVE-2026-64075fprobe: Fix unregister_fprobe() to wait for RCU grace periodGracelessExithttps://gracelessexit.day CVE-2026-64048net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slotEmptySlotMachinehttps://emptyslotmachine.money CVE-2026-64074fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmapSlabAvalanchehttps://slabavalanche.rocks CVE-2026-64073irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RTWorkAfterDeathhttps://workafterdeath.rip CVE-2026-64072nvme: fix bio leak on mapping failureBioHazardhttps://biohazard.zip CVE-2026-64071nvme-pci: fix use-after-free in nvme_free_host_mem()HostBustershttps://hostbusters.com CVE-2026-64070powerpc/hv-gpci: fix preempt count leak in sysfs show pathsShowStopperhttps://showstopper.tv CVE-2026-64069netfs: Fix cancellation of a DIO and single read subrequestsCancelCulturehttps://cancelculture.wtf CVE-2026-64068netfs: Fix missing locking around retry adding new subreqsRetryHardhttps://retryhard.io CVE-2026-64067netfs: Fix missing barriers when accessing stream->subrequests locklesslyBarrierReefhttps://barrierreef.stream CVE-2026-64066netfs: Fix netfs_read_to_pagecache() to pause on subreq failurePauseForConcernhttps://pauseforconcern.media CVE-2026-64065netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() callPortfolioBughttps://portfoliobug.art CVE-2026-64047net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ringOneLinkShorthttps://onelinkshort.link CVE-2026-64064netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes goneDirtyLaundryhttps://dirtylaundry.exposed CVE-2026-64063netfs: Fix streaming write being overwrittenStreamSnipedhttps://streamsniped.stream CVE-2026-64062netfs: Fix potential deadlock in write-through modeWriteOfTheDeadhttps://writeofthedead.zone CVE-2026-64061netfs: Fix early put of sink folio in netfs_read_gaps()SinkingFeelinghttps://sinkingfeeling.fail CVE-2026-64060netfs: Fix leak of request in netfs_write_begin() error handlingLeakyBeginningshttps://leakybeginnings.plumbing CVE-2026-64059netfs: Fix folio->private handling in netfs_perform_write()PrivatePartshttps://privateparts.exposed CVE-2026-64058netfs: Fix netfs_read_folio() to wait on writebackWaitWatchershttps://waitwatchers.fit CVE-2026-64057afs: Fix the locking used by afs_get_link()WeakestLinkhttps://weakestlink.tv CVE-2026-64056net: ethernet: cortina: Make RX SKB per-portAnyPortInAStormhttps://anyportinastorm.surf CVE-2026-64055net: ethernet: cortina: Carry over frag counterCarryOnFragginghttps://carryonfragging.gg CVE-2026-64046net: tls: prevent chain-after-chain in plain text SGChainSmokerhttps://chainsmoker.dj CVE-2026-64015security/keys: fix missed RCU read section on lookupKeylessEntryhttps://keylessentry.estate CVE-2026-64024tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN predictionISNstradamushttps://isnstradamus.biz CVE-2026-64023gpio: aggregator: fix a potential use-after-freeAggroGatehttps://aggrogate.io CVE-2026-64022gpio: aggregator: remove the software node when deactivating the aggregatorGhostNodehttps://ghostnode.cloud CVE-2026-64021drm/xe/oa: Fix exec_queue leak on width check in stream openQueueTipshttps://queuetips.dev CVE-2026-64020nvme-pci: fix dma_vecs leak on p2p memoryPeerReviewFailedhttps://peerreviewfailed.science CVE-2026-64019nvme-pci: fix dma mapping leak on data setup errorMapLeakshttps://mapleaks.news CVE-2026-64018net: mana: validate rx_req_idx to prevent out-of-bounds array accessManaOverflowhttps://manaoverflow.gg CVE-2026-64044ovpn: respect peer refcount in CMD_NEW_PEER error pathPeerReviewhttps://peerreview.science CVE-2026-64043ovpn: fix race between deleting interface and adding new peerDisapPeeredhttps://disappeered.io CVE-2026-64042vfio/pci: Check BAR resources before exporting a DMABUFBARFighthttps://barfight.lol CVE-2026-64041ASoC: codecs: fs210x: fix possible buffer overflowCodecBluehttps://codecblue.audio CVE-2026-64040cachefiles: Fix error return when vfs_mkdir() failsMkdirtyDeedshttps://mkdirtydeeds.cheap CVE-2026-64039drm/msm/snapshot: fix dumping of the unaligned regionsDumpAndDumperhttps://dumpanddumper.film CVE-2026-64038hwmon: (lm90) Stop work before releasing hwmon deviceCantStopWontStophttps://cantstopwontstop.work CVE-2026-64037wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabledGeneralTSOhttps://generaltso.pizza CVE-2026-64036cgroup/rstat: validate cpu before css_rstat_cpu() accessOffTheChartshttps://offthecharts.top CVE-2026-64035igc: set tx buffer type for SMD framesFrameJobhttps://framejob.art CVE-2026-64017blk-mq: pop cached request if it is usablePopGoesTheRequesthttps://popgoestherequest.lol CVE-2026-64034net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA bufferFetchHappenshttps://fetchhappens.dog CVE-2026-64033RDMA/rtrs: Fix use-after-free in path file creation cleanupPathoLogicalhttps://pathological.direct CVE-2026-64032bridge: mcast: Fix a possible use-after-free when removing a bridge portBurnedBridgeshttps://burnedbridges.estate CVE-2026-64031erofs: fix managed cache race for unaligned extentsExtentOfTheDamagehttps://extentofthedamage.lawyer CVE-2026-64030wifi: mac80211: bounds-check link_id in ieee80211_ml_epcsLinkedOuthttps://linkedout.biz CVE-2026-64029ALSA: seq: Serialize UMP output teardown with event_inputUMPluggedhttps://umplugged.audio CVE-2026-64028tracing: Avoid NULL return from hist_field_name() on truncationTruncatedHistoryhttps://truncatedhistory.news CVE-2026-64027net: shaper: rework the VALID marking (again)ShapeShifterhttps://shapeshifter.fit CVE-2026-64026rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsgSpliceGirlshttps://splicegirls.fm CVE-2026-64025bpf, skmsg: fix verdict sk_data_ready racing with ktls rxRushedVerdicthttps://rushedverdict.lawyer CVE-2026-64016ksmbd: fix durable reconnect error path file lifetimeReconnectFourhttps://reconnectfour.party CVE-2026-63989bridge: Fix sleep in atomic context in netlink pathAtomicNaphttps://atomicnap.energy CVE-2026-63998ethtool: module: call ethnl_ops_complete() on module flash errorsUnfinishedBusinesshttps://unfinishedbusiness.biz CVE-2026-63997ethtool: module: avoid leaking a netdev ref on module flash errorsRefMadnesshttps://refmadness.film CVE-2026-63996ethtool: cmis: require exact CDB reply lengthCurtReplyhttps://curtreply.chat CVE-2026-63995ethtool: cmis: validate start_cmd_payload_size from modulePayloadedQuestionhttps://payloadedquestion.lol CVE-2026-63994tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()CowTippinghttps://cowtipping.farm CVE-2026-63993vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()StaleMatehttps://stalemate.day CVE-2026-63992tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()TunnelVisionhttps://tunnelvision.tv CVE-2026-64014Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer sizeOutOfTouchhttps://outoftouch.fm CVE-2026-64013ACPI: button: Fix ACPI GPE handler leak during removalButtonMasherhttps://buttonmasher.gg CVE-2026-64012net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peekedPeekPerformancehttps://peekperformance.fit CVE-2026-64011nfc: llcp: Fix use-after-free in llcp_sock_release()TapAndDiehttps://tapanddie.money CVE-2026-64010nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()CCYouLaterhttps://ccyoulater.chat CVE-2026-64009xfrm: Check for underflow in xfrm_state_mtuMTUnderflowhttps://mtunderflow.zip CVE-2026-63991Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()SendInTheCloneshttps://sendintheclones.army CVE-2026-64008accel/rocket: fix UAF via dangling GEM handle in create_boDanglingGEMhttps://danglinggem.rocks CVE-2026-64007netfilter: synproxy: refresh tcphdr after skb_ensure_writableSynfulProxyhttps://synfulproxy.church CVE-2026-64006netfilter: nf_tables: fix dst corruption in same register operationCorruptRegisterhttps://corruptregister.vote CVE-2026-64005net/smc: Do not re-initialize smc hashtablesReHashedhttps://rehashed.kitchen CVE-2026-64004net/iucv: fix locking in .getsockoptSockOptOuthttps://sockoptout.us CVE-2026-64003scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queuesQueueJumperhttps://queuejumper.horse CVE-2026-64002ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()UnreservedSeatinghttps://unreservedseating.aero CVE-2026-64001ALSA: pcm: oss: Fix setup list UAF on proc write errorOSSuaryhttps://ossuary.rip CVE-2026-64000net: hsr: fix potential OOB access in supervision frame handlingUnsupervisedLearninghttps://unsupervisedlearning.academy CVE-2026-63999ethtool: rss: fix indir_table and hkey leak on get_rxfh failureHashSlingingLeakerhttps://hashslingingleaker.restaurant CVE-2026-63990bonding: refuse to enslave CAN devicesCANtTouchThishttps://canttouchthis.dance CVE-2026-63947Bluetooth: HIDP: fix missing length checks in hidp_input_report()HIDPandSeekhttps://hidpandseek.games CVE-2026-63956USB: serial: cypress_m8: fix memory corruption with small endpointCypressHillhttps://cypresshill.dj CVE-2026-63955mm/vmalloc: do not trigger BUG() on BH disabled contextBottomHalfEmptyhttps://bottomhalfempty.bar CVE-2026-63954hpfs: fix a crash if hpfs_map_dnode_bitmap failsBitmapOfNowherehttps://bitmapofnowhere.travel CVE-2026-63953mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_pageMigratoryLeakhttps://migratoryleak.aero CVE-2026-63952memfd: deny writeable mappings when implying SEAL_WRITESealOfDisapprovalhttps://sealofdisapproval.vote CVE-2026-63988bridge: Fix sleep in atomic context in sysfs pathAtomicSnoozehttps://atomicsnooze.day CVE-2026-63987ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILESDIMWittedhttps://dimwitted.wtf CVE-2026-63951zram: fix use-after-free in zram_writeback_endioZombieRAMhttps://zombieram.rip CVE-2026-63986ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failureErrPointerSistershttps://errpointersisters.band CVE-2026-63985ethtool: eeprom: add more safeties to EEPROM Netlink fallbackFallbackBoyhttps://fallbackboy.fm CVE-2026-63984ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()DecompressionSicknesshttps://decompressionsickness.zip CVE-2026-63983net/sched: fix packet loop on netem when duplicate is onLoopDreamshttps://loopdreams.film CVE-2026-63982net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loopMirredImagehttps://mirredimage.art CVE-2026-63981net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflowRecursionExcursionhttps://recursionexcursion.travel CVE-2026-63980net/handshake: Use spin_lock_bh for hn_lockSecretHandshakehttps://secrethandshake.club CVE-2026-63979net/handshake: hand off the pinned file reference to accept_doitHandMeDownhttps://handmedown.fashion CVE-2026-63978net/handshake: Drain pending requests at net namespace exitLeftHanginghttps://lefthanging.fail CVE-2026-63977dpll: zl3073x: use __dpll_device_change_ntf() and remove change_workSpareChangehttps://sparechange.money CVE-2026-63950mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_oneOneMapWonderhttps://onemapwonder.page CVE-2026-63976Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration successEcredScorehttps://ecredscore.money CVE-2026-63975Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rspEcredCrunchhttps://ecredcrunch.fail CVE-2026-63974Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device closeDrainedToothhttps://drainedtooth.dental CVE-2026-63973net: mana: Add NULL guards in teardown path to prevent panic on attach failureOutOfManahttps://outofmana.gg CVE-2026-63972net: mana: Skip redundant detach on already-detached portDetachedManahttps://detachedmana.lol CVE-2026-63971sctp: fix race between sctp_wait_for_connect and peeloffSlipperyPeelhttps://slipperypeel.fail CVE-2026-63970vsock/virtio: bind uarg before filling zerocopy skbZeroCopyCathttps://zerocopycat.cat CVE-2026-63969ipv6: fix possible infinite loop in rt6_fill_node()RouteSixtyLoophttps://routesixtyloop.us CVE-2026-63968ipv6: fix possible infinite loop in fib6_select_path()EndlessFibhttps://endlessfib.news CVE-2026-63967iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO bufferFifoLeakshttps://fifoleaks.news CVE-2026-63949auxdisplay: line-display: fix OOB read on zero-length message_store()BetweenTheLineshttps://betweenthelines.art CVE-2026-63966iio: imu: adis16550: fix stack leak in trigger handlerTriggerHappyhttps://triggerhappy.io CVE-2026-63965iio: pressure: bmp280: fix stack leak in bmp580 trigger handlerUnderPressurehttps://underpressure.fm CVE-2026-63964usb: typec: ucsi: ccg: reject firmware images without a ':' record headerMissingColonhttps://missingcolon.wtf CVE-2026-63963usb: typec: tcpm: validate VDO count in Discover Identity ACK handlersIdentityThefthttps://identitytheft.money CVE-2026-63962usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()ModeBuffethttps://modebuffet.pizza CVE-2026-63961usb: typec: altmodes/displayport: validate count before reading Status Update VDOStatusAnxietyhttps://statusanxiety.chat CVE-2026-63960usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()SmugglersCovehttps://smugglerscove.rocks CVE-2026-63959usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNTMaximOverdrivehttps://maximoverdrive.film CVE-2026-63958usb: typec: ucsi: validate connector number in ucsi_connector_change()ConnectorFourhttps://connectorfour.gg CVE-2026-63957USB: serial: safe_serial: fix memory corruption with small endpointNotSoSafeSerialhttps://notsosafeserial.fail CVE-2026-63948Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !connLeakyChannelhttps://leakychannel.tv CVE-2026-63906usb: musb: omap2430: Fix use-after-free in omap2430_probe()MusbBeFreehttps://musbbefree.lol CVE-2026-63915nfc: hci: fix out-of-bounds read in HCP header parsingOutOfHeadershttps://outofheaders.news CVE-2026-63914xfrm: route MIGRATE notifications to caller's netnsMigrationSeasonhttps://migrationseason.aero CVE-2026-63913netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction checkRstInPeacehttps://rstinpeace.rip CVE-2026-63912xfrm: esp: restore combined single-frag length gateFragGatehttps://fraggate.news CVE-2026-63911xfrm: iptfs: reset runtime state when cloning SAsAttackOfTheCloneshttps://attackoftheclones.movie CVE-2026-63946Bluetooth: ISO: fix UAF in iso_recv_frameFreezeFramehttps://freezeframe.fm CVE-2026-63910dma-buf: fix UAF in dma_buf_fd() tracepointTracePointBlankhttps://tracepointblank.wtf CVE-2026-63945Bluetooth: ISO: serialize iso_sock_clear_timer with socket lockIsoOutOfSynchttps://isooutofsync.day CVE-2026-63944Bluetooth: hci_sync: fix UAF in hci_le_create_cis_syncSyncOrSwimhttps://syncorswim.fail CVE-2026-63943Input: xpad - fix out-of-bounds access for Share buttonOverSharehttps://overshare.lol CVE-2026-63942parport: Fix race between port and client registrationParallelParkinghttps://parallelparking.fail CVE-2026-63941KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisorVectorVictorhttps://vectorvictor.aero CVE-2026-63940KVM: SEV: Ignore Port I/O requests of length '0'MuchAdoAboutZerohttps://muchadoaboutzero.art CVE-2026-63939KVM: SEV: Compute the correct max length of the in-GHCB scratch areaScratchThathttps://scratchthat.dj CVE-2026-63938KVM: SEV: Check PSC request indices against the actual size of the bufferIndexFundhttps://indexfund.money CVE-2026-63937KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC bufferReadOnceLiveTwicehttps://readoncelivetwice.film CVE-2026-63936iio: adc: mt6359: fix unchecked return value in mt6358_read_impUncheckedBaggagehttps://uncheckedbaggage.aero CVE-2026-63909ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loopsAceVenturerhttps://aceventurer.dog CVE-2026-63935iio: adc: nxp-sar-adc: fix division by zero in write_rawDivisionByZorrohttps://divisionbyzorro.horse CVE-2026-63934iio: gyro: itg3200: fix i2c read into the wrong stack locationMisplacedGyrohttps://misplacedgyro.pizza CVE-2026-63933iio: gyro: adis16260: fix division by zero in write_rawZeroSpinhttps://zerospin.fit CVE-2026-63932iio: chemical: mhz19b: reject oversized serial repliesCarbonOverloadhttps://carbonoverload.energy CVE-2026-63931iio: chemical: scd30: fix division by zero in write_rawNetZeroDivisionhttps://netzerodivision.vote CVE-2026-63930iio: buffer: hw-consumer: fix use-after-free in error pathConsumerRegrethttps://consumerregret.money CVE-2026-63929iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()LeakyFencehttps://leakyfence.estate CVE-2026-63928USB: serial: omninet: fix memory corruption with small endpointOmniShambleshttps://omnishambles.wtf CVE-2026-63927usb: dwc2: Fix use after free in debug codePostMortemDebughttps://postmortemdebug.rip CVE-2026-63926bpf: sockmap: fix tail fragment offset in bpf_msg_push_dataPushItRealBadhttps://pushitrealbad.fm CVE-2026-63908Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_memTouchAndGohttps://touchandgo.aero CVE-2026-63925macsec: fix replay protection at XPN lower-PN wrapReplayItAgainSamhttps://replayitagainsam.film CVE-2026-63924ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()JumboHopscotchhttps://jumbohopscotch.scot CVE-2026-63923octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notifyBodySnatchershttps://bodysnatchers.film CVE-2026-63922ipv6: exthdrs: refresh nh after handling HAO optionHaoNowBrownCowhttps://haonowbrowncow.lol CVE-2026-63921ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().CarpalTunnelhttps://carpaltunnel.health CVE-2026-63920ipv6: validate extension header length before copying to cmsgHeadOverHeelshttps://headoverheels.fm CVE-2026-63919xfrm: input: hold netns during deferred transport reinjectionBoosterShothttps://boostershot.fit CVE-2026-63918l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifnameZeroRefsGivenhttps://zerorefsgiven.wtf CVE-2026-63917ip6: vti: Use ip6_tnl.net in vti6_changelink().WrongWayTunnelhttps://wrongwaytunnel.us CVE-2026-63916HID: wacom: Fix OOB write in wacom_hid_set_device_mode()OutsideTheLineshttps://outsidethelines.art CVE-2026-63907uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memoryBuyOneGetOneFreehttps://buyonegetonefree.money CVE-2026-63875arm64: tlb: Flush walk cache when unsharing PMD tablesCourtesyFlushhttps://courtesyflush.fail CVE-2026-63884drm/i915: Fix potential UAF in TTM object purgePurgeAfterReadinghttps://purgeafterreading.film CVE-2026-63883serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQGeniInABottlehttps://geniinabottle.fm CVE-2026-63882drm/amdkfd: fix NULL pointer bug in svm_range_set_attrFreeRangeNullhttps://freerangenull.horse CVE-2026-63881drm/amdkfd: fix a vulnerability of integer overflow in kfd debuggerDebuggerOverboardhttps://debuggeroverboard.film CVE-2026-63880drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFOLockedOutOfMemoryhttps://lockedoutofmemory.fail CVE-2026-63879drm/amdgpu: fix amdgpu_hmm_range_get_pagesHmmThatsOddhttps://hmmthatsodd.wtf CVE-2026-63905usbip: vudc: Fix use after free bug in vudc_remove due to race conditionVirtualInsanityhttps://virtualinsanity.fm CVE-2026-63878drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFOUncountedGemshttps://uncountedgems.money CVE-2026-63904usb: usbtmc: check URB actual_length for interrupt-IN notificationsActualSizeMayVaryhttps://actualsizemayvary.lol CVE-2026-63903USB: serial: belkin_sa: validate interrupt status lengthShortStatushttps://shortstatus.chat CVE-2026-63902USB: serial: cypress_m8: validate interrupt packet headersCypressSpillhttps://cypressspill.fm CVE-2026-63901USB: serial: digi_acceleport: fix memory corruption with small endpointsSpeedBumphttps://speedbump.fail CVE-2026-63900USB: serial: keyspan: fix missing indat transfer sanity checkKeyspanInsanityhttps://keyspaninsanity.wtf CVE-2026-63899USB: serial: mxuport: fix memory corruption with small endpointPointOfNoReturnhttps://pointofnoreturn.fm CVE-2026-63898USB: serial: mct_u232: fix memory corruption with small endpointUBoat232https://uboat232.rip CVE-2026-63897USB: serial: mct_u232: fix missing interrupt-in transfer sanity checkPeriscopeDownhttps://periscopedown.fail CVE-2026-63896usb: gadget: composite: fix integer underflow in WebUSB GET_URL handlingSixFeetUnderflowhttps://sixfeetunderflow.rip CVE-2026-63895usb: gadget: f_fs: copy only received bytes on short ep0 readShortChangedhttps://shortchanged.money CVE-2026-63877serial: dz: Convert to use a platform deviceDzNutshttps://dznuts.lol CVE-2026-63894usb: gadget: f_fs: serialize DMABUF cancel against request completionUncancellablehttps://uncancellable.wtf CVE-2026-63893thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()ThunderWraphttps://thunderwrap.pizza CVE-2026-63892thunderbolt: property: Reject dir_len < 4 to prevent size_t underflowThunderFromDownUnderhttps://thunderfromdownunder.fm CVE-2026-63891thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()RecursionConcussionhttps://recursionconcussion.io CVE-2026-63890scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walkerFipFlophttps://fipflop.fail CVE-2026-63889scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32NarrowMindedhttps://narrowminded.wtf CVE-2026-63888scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()CrcAndBurnhttps://crcandburn.fail CVE-2026-63887scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_bufRunOnSentencehttps://runonsentence.chat CVE-2026-63886scsi: target: iscsi: Validate CHAP_R length before base64 decodeChapStickhttps://chapstick.lol CVE-2026-63885drm/gem: fix race between change_handle and handle_deleteHandleWithoutCarehttps://handlewithoutcare.fm CVE-2026-63876serial: zs: Convert to use a platform deviceCatchingZshttps://catchingzs.day CVE-2026-63874net: mctp: usb: fix race between urb completion and rx_retry cancellationTryTryRaceAgainhttps://trytryraceagain.horse CVE-2026-63872esp: fix page frag reference leak on skb_to_sgvec failureEauDeFraghttps://eaudefrag.lol CVE-2026-63873accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()StructuralLeakagehttps://structuralleakage.estate CVE-2026-63870ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()StickyPanhttps://stickypan.pizza CVE-2026-63871Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route callsRouteRagehttps://routerage.wtf CVE-2026-63869wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotapAntennaGatehttps://antennagate.news CVE-2026-63867mptcp: close TOCTOU race while computing rcv_wndWindowShoppinghttps://windowshopping.money CVE-2026-63868net: garp: fix unsigned integer underflow in garp_pdu_parse_attrAccordingToGarphttps://accordingtogarp.film CVE-2026-63855drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec ringsNoFenceIntendedhttps://nofenceintended.lol CVE-2026-63864bpf: Propagate error from visit_tailcall_insnTailFailhttps://tailfail.fail CVE-2026-63863drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm()UnLocknesshttps://unlockness.scot CVE-2026-63862PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not foundDomainSquatterhttps://domainsquatter.biz CVE-2026-63861spi: mtk-snfi: unregister ECC engine on probe failure and remove() callbackEccentricEnginehttps://eccentricengine.rocks CVE-2026-63860RDMA/core: Prefer NLA_NUL_STRINGNulAndVoidhttps://nulandvoid.lawyer CVE-2026-63859net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()MissingBitshttps://missingbits.stream CVE-2026-63858netfilter: nf_tables: add hook transactions for device deletionsOffTheHookhttps://offthehook.fish CVE-2026-63857net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()FragNarokhttps://fragnarok.gg CVE-2026-63866wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()WcidThisWayhttps://wcidthisway.com CVE-2026-63865bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooksSleeperHookhttps://sleeperhook.rest CVE-2026-63856drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec ringsPicketFencehttps://picketfence.garden CVE-2026-63846drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ringOnTheFencehttps://onthefence.vote CVE-2026-63845drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ringDefencelessJpeghttps://defencelessjpeg.art CVE-2026-63844drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ringPicketFailhttps://picketfail.fail CVE-2026-63843drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ringFenceHopperhttps://fencehopper.horse CVE-2026-63842drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ringGoodFencesBadRingshttps://goodfencesbadrings.estate CVE-2026-63841drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ringFenceSitterhttps://fencesitter.fyi CVE-2026-63840drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ringMasterFencerhttps://masterfencer.sport CVE-2026-63839platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()LeakPadhttps://leakpad.plumbing CVE-2026-63854drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec ringsElectricFencehttps://electricfence.energy CVE-2026-63853drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ringChainLinkedhttps://chainlinked.money CVE-2026-63852drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ringBarbedWiredhttps://barbedwired.band CVE-2026-63851drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ringAmericanDreamFencehttps://americandreamfence.us CVE-2026-63850drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ringBeyondThePalehttps://beyondthepale.beer CVE-2026-63849drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ringUnFencedFrontierhttps://unfencedfrontier.land CVE-2026-63848drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ringDontFenceMeInhttps://dontfencemein.fm CVE-2026-63847drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ringWhitewashedFencehttps://whitewashedfence.page CVE-2026-63837net: ena: PHC: Check return code before setting timestamp outputTimestampOfApprovalhttps://timestampofapproval.day CVE-2026-63838ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]DaiHardhttps://daihard.audio CVE-2026-63800pNFS: Fix use-after-free in pnfs_update_layout()LayoutToResthttps://layouttorest.rip CVE-2026-63809bpf: use kvfree() for replaced sysctl write bufferMisFreesancehttps://misfreesance.legal CVE-2026-63808exfat: fix potential use-after-free in exfat_find_dir_entry()GhostEntryhttps://ghostentry.house CVE-2026-63807KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping levelHugeMistakehttps://hugemistake.wtf CVE-2026-63806KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()BugOnArrivalhttps://bugonarrival.aero CVE-2026-63805crypto: nx - fix nx_crypto_ctx_exit argumentPointlessArgumenthttps://pointlessargument.chat CVE-2026-63804gfs2: fix use-after-free in gfs2_qd_deallocQuotaTheDayhttps://quotatheday.today CVE-2026-63836batman-adv: tp_meter: avoid divide-by-zero for dec_cwndZeroDarkThroughputhttps://zerodarkthroughput.film CVE-2026-63835batman-adv: v: prevent OGM aggregation on disabled hardifGothamBroadcasthttps://gothambroadcast.news CVE-2026-63834batman-adv: tp_meter: restrict number of unacked list entriesAckHoarderhttps://ackhoarder.storage CVE-2026-63833ntfs3: reject direct userspace writes to reserved $LX* xattrsReservedNoMorehttps://reservednomore.restaurant CVE-2026-63832wifi: mt76: add wcid publish check in mt76_sta_addPrematurePublicationhttps://prematurepublication.press CVE-2026-63831mac802154: llsec: add skb_cow_data() before in-place cryptoHolyCowDatahttps://holycowdata.farm CVE-2026-63830net: skmsg: preserve sg.copy across SG transformsLostInTransformhttps://lostintransform.tokyo CVE-2026-63803hdlc_ppp: sync per-proto timers before freeing hdlc stateTimerAfterTimehttps://timeraftertime.radio CVE-2026-63829net: ip_gre: require CAP_NET_ADMIN in the device netns for changelinkCapInHandhttps://capinhand.cash CVE-2026-63828apparmor: mediate the implicit connect of TCP fast open sendmsgFastAndFurtivehttps://fastandfurtive.racing CVE-2026-63827apparmor: fix use-after-free in rawdata dedup loopDedupOrAlivehttps://deduporalive.dance CVE-2026-63826fbdev: fix use-after-free in store_modes()GhostOfModesPasthttps://ghostofmodespast.christmas CVE-2026-63825gcov: use atomic counter updates to fix concurrent access crashesLosingCounthttps://losingcount.accountant CVE-2026-63824KEYS: fix overflow in keyctl_pkey_params_get_2()OverKeyedhttps://overkeyed.dj CVE-2026-63823keys: Pin request_key_auth payload in instantiate pathsLostAuthorityhttps://lostauthority.city CVE-2026-63822wifi: ath11k: fix warning when unbindingUnbindingContracthttps://unbindingcontract.ink CVE-2026-63821wifi: rtw88: usb: fix memory leaks on USB write failuresThumbDriphttps://thumbdrip.download CVE-2026-63820f2fs: fix missing read bio submission on large folio errorUnsentBiohttps://unsentbio.date CVE-2026-63802blk-cgroup: fix UAF in __blkcg_rstat_flush()RoyalFlushedhttps://royalflushed.poker CVE-2026-63819f2fs: fix to do sanity check on f2fs_get_node_folio_ra()InsanityCheckhttps://insanitycheck.clinic CVE-2026-63818f2fs: validate orphan inode entry countLittleOrphanInodehttps://littleorphaninode.show CVE-2026-63817f2fs: validate compress cache inode only when enabledPhantomCompressionhttps://phantomcompression.zip CVE-2026-63816f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inodeAtomicWedgiehttps://atomicwedgie.lol CVE-2026-63815f2fs: bound i_inline_xattr_size for non-inline-xattr inodesXattrLargehttps://xattrlarge.pizza CVE-2026-63814f2fs: validate ACL entry sizes in f2fs_acl_from_disk()TornAclhttps://tornacl.rehab CVE-2026-63813Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"Revertigohttps://revertigo.film CVE-2026-63812f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()ExtentuatingCircumstanceshttps://extentuatingcircumstances.lawyer CVE-2026-63811f2fs: read COW data with the original inode during atomic writeHolyCowhttps://holycow.farm CVE-2026-63810block: Avoid mounting the bdev pseudo-filesystem in userspacePseudoMounthttps://pseudomount.horse CVE-2026-63801tipc: fix slab-use-after-free Read in tipc_aead_decrypt_doneDecryptKeeperhttps://decryptkeeper.rip CVE-2026-53398NFSD: Fix SECINFO_NO_NAME decode error cleanupNamelessDreadhttps://namelessdread.wtf CVE-2026-53397nfsd: fix posix_acl leak on SETACL decode failureAclInTheHolehttps://aclinthehole.golf CVE-2026-53396nfsd: fix posix_acl leak and ignored error in nfsd4_create_fileCreativeLeakinghttps://creativeleaking.art CVE-2026-53395nfsd: fix dead ACL conflict guard in nfsd4_createSleepingGuardhttps://sleepingguard.fail CVE-2026-53394nfsd: avoid leaking pre-allocated openowner on unconfirmed retry raceOwnerlessManorhttps://ownerlessmanor.estate CVE-2026-53393nfsd: reset write verifier on deferred writeback errorsTrustButVerifierhttps://trustbutverifier.news CVE-2026-53392NFSv4/flexfiles: reject zero filehandle version countZeroHandleGivenhttps://zerohandlegiven.ninja CVE-2026-63799sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup pathClearAndPresentDangerhttps://clearandpresentdanger.film CVE-2026-63798irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on removeChainOfFoolshttps://chainoffools.fm CVE-2026-53391NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addrNoFixedAddresshttps://nofixedaddress.estate CVE-2026-63797rpmsg: char: Fix use-after-free on probe error pathDeadLetterOfficehttps://deadletteroffice.email CVE-2026-63796ocfs2: reject oversized group bitmap descriptorsObeseBitmaphttps://obesebitmap.fit CVE-2026-637959p: avoid putting oldfid in p9_client_walk() error pathBadFidohttps://badfido.dog CVE-2026-63794KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT pathCryptOverrunhttps://cryptoverrun.money CVE-2026-63793ntfs: serialize volume label accessesOffLabelhttps://offlabel.pharmacy CVE-2026-53403fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_varModelNoShowhttps://modelnoshow.fashion CVE-2026-53402fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()FontOfAllEvilhttps://fontofallevil.art CVE-2026-53401fbdev: omap2: fix use-after-free in omapfb_mmapMmapFromTheGravehttps://mmapfromthegrave.rip CVE-2026-53400i2c: core: fix adapter registration raceRegistrationDerbyhttps://registrationderby.bet CVE-2026-53399nfsd: release layout stid on setlease failureBrokenLeasehttps://brokenlease.rent CVE-2026-53389net/tcp-ao: fix use-after-free of key in del_async pathSkeletonKeyhttps://skeletonkey.house CVE-2026-53390ksmbd: fix out-of-bounds read in smb_check_perm_dacl()DaclAndCoverhttps://daclandcover.us CVE-2026-53388fuse: re-lock request before replacing page cache folioShortFusehttps://shortfuse.energy CVE-2026-53387iio: light: veml6075: add bounds check to veml6075_it_ms indexSunburnIndexhttps://sunburnindex.day CVE-2026-53386iio: adc: ti-ads1298: add bounds check to pga_settings indexGainOfFunctionhttps://gainoffunction.bio CVE-2026-53385vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_writeConsoleYourselfhttps://consoleyourself.chat CVE-2026-53384serial: 8250_dw: unregister 8250 port if clk_notifier_register() failsPortOfNoReturnhttps://portofnoreturn.cruises CVE-2026-53383ksmbd: reject non-VALID session in compound request branchSessionCrasherhttps://sessioncrasher.party CVE-2026-53381virtiofs: fix UAF on submount umountSunkenSubmounthttps://sunkensubmount.rocks CVE-2026-53382media: vidtv: fix NULL pointer dereference in vidtv_mux_push_siDeadAirhttps://deadair.tv CVE-2026-53380media: rzv2h-ivc: Fix concurrent buffer list accessBufferingForeverhttps://bufferingforever.stream CVE-2026-53379media: i2c: ov8856: free control handler on error in ov8856_init_controls()OutOfControlshttps://outofcontrols.camera CVE-2026-53378drm/colorop: Fix blob property reference tracking in state lifecycleColorOutOfSpacehttps://coloroutofspace.space CVE-2026-53377drm/msm: always recover the gpuLeftForDeadhttps://leftfordead.gg CVE-2026-53376drm/amdkfd: Add upper bound check for num_of_nodesNodeLimitHoldemhttps://nodelimitholdem.casino CVE-2026-53375drm/amdgpu/vce: Prevent partial address patchesPatchyAtBesthttps://patchyatbest.reviews CVE-2026-53373mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap()PrematureUnmappinghttps://prematureunmapping.travel CVE-2026-53374drm/amdgpu: zero-initialize GART table on allocationDirtyGartyhttps://dirtygarty.party CVE-2026-53372iommu/vt-d: Block PASID attachment to nested domain with dirty trackingDirtyNesthttps://dirtynest.homes CVE-2026-53371RDMA/ionic: bound node_desc sysfs read with %.64sDescGoneWildhttps://descgonewild.tv CVE-2026-53370perf/x86/intel: Improve validation and configuration of ACR masksMaskOffhttps://maskoff.club CVE-2026-53369udf: reject descriptors with oversized CRC lengthCrcYouLaterhttps://crcyoulater.surf CVE-2026-53367selinux: fix avdcache auditingCookingTheCachehttps://cookingthecache.money CVE-2026-53368f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usageFsckAroundFindOuthttps://fsckaroundfindout.wtf