| CVE-2026-64164 | btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() | SnoozeButterFS | https://snoozebutterfs.zip |
| CVE-2026-64173 | tracing: Do not call map->ops->elt_free() if elt_alloc() fails | PhantomFree | https://phantomfree.lol |
| CVE-2026-64172 | KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235) | IPIFreely | https://ipifreely.dog |
| CVE-2026-64171 | i2c: tegra: fix pm_runtime leak on mutex_lock failure | SleeplessInTegra | https://sleeplessintegra.day |
| CVE-2026-64170 | spi: qup: fix error pointer deref after DMA setup failure | SpiKids | https://spikids.film |
| CVE-2026-64169 | spi: ep93xx: fix error pointer deref after DMA setup failure | SpiGame | https://spigame.stream |
| CVE-2026-64168 | spi: sprd: fix error pointer deref after DMA setup failure | SpiVsSpi | https://spivsspi.gg |
| CVE-2026-64167 | kho: skip KHO for crash kernel | KhoLateral | https://kholateral.fail |
| CVE-2026-64186 | iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs | IommOops | https://iommoops.wtf |
| CVE-2026-64185 | sysfs: don't remove existing directory on update failure | DirNoMore | https://dirnomore.rip |
| CVE-2026-64184 | mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() | DAMONSpawn | https://damonspawn.horse |
| CVE-2026-64166 | firmware: arm_ffa: Check for NULL FF-A ID table while driver registration | FFAndLoathing | https://ffandloathing.film |
| CVE-2026-64183 | efi: Allocate runtime workqueue before ACPI init | EFIBird | https://efibird.aero |
| CVE-2026-64182 | drivers/base/memory: fix memory block reference leak in poison accounting | PoisonAccountant | https://poisonaccountant.money |
| CVE-2026-64181 | mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_special() | AbnormalPage | https://abnormalpage.page |
| CVE-2026-64180 | mm/memory_hotplug: fix memory block reference leak on remove | HotUnplugged | https://hotunplugged.fm |
| CVE-2026-64179 | net: wwan: iosm: fix potential memory leaks in ipc_imem_init() | WWANted | https://wwanted.us |
| CVE-2026-64178 | Bluetooth: bnep: Fix UAF read of dev->name | NameDropper | https://namedropper.chat |
| CVE-2026-64177 | phonet/pep: disable BH around forwarded sk_receive_skb() | PepRally | https://peprally.party |
| CVE-2026-64176 | wifi: iwlwifi: mvm: fix driver-set TX rates on old devices | RateExpectations | https://rateexpectations.news |
| CVE-2026-64175 | wifi: iwlwifi: mld: stop TX during firmware restart | TXInterrupted | https://txinterrupted.film |
| CVE-2026-64174 | wifi: cfg80211: advance loop vars in cfg80211_merge_profile() | ProfileSpinner | https://profilespinner.dj |
| CVE-2026-64165 | ARM: integrator: Fix early initialization | DisIntegrator | https://disintegrator.energy |
| CVE-2026-64123 | net: hsr: defer node table free until after RCU readers | HSRDerailed | https://hsrderailed.fail |
| CVE-2026-64132 | ipv6: ioam: refresh hdr pointer before ioam6_event() | IOAMnesia | https://ioamnesia.wtf |
| CVE-2026-64131 | mm/memory: fix spurious warning when unmapping device-private/exclusive pages | WarnOut | https://warnout.rest |
| CVE-2026-64130 | mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free | ZeroFolioGiven | https://zerofoliogiven.lol |
| CVE-2026-64129 | mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page | SpinCity | https://spincity.tv |
| CVE-2026-64128 | Bluetooth: ISO: drop ISO_END frames received without prior ISO_START | ISOEndGame | https://isoendgame.gg |
| CVE-2026-64163 | test_kprobes: clear kprobes between test runs | LingeringProbe | https://lingeringprobe.exposed |
| CVE-2026-64127 | Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer | StackOverShare | https://stackovershare.dev |
| CVE-2026-64162 | idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() | ClockBlocked | https://clockblocked.watch |
| CVE-2026-64161 | net: ti: icssm-prueth: fix eth_ports_node leak in probe | PortAuthority | https://portauthority.nyc |
| CVE-2026-64160 | netfs: Fix potential for tearing in ->remote_i_size and ->zero_point | TearJerker | https://tearjerker.stream |
| CVE-2026-64159 | netfs: Fix zeropoint update where i_size > remote_i_size | ZeroPointBreak | https://zeropointbreak.surf |
| CVE-2026-64158 | netfs: Fix write streaming disablement if fd open O_RDWR | ReadWriteWrong | https://readwritewrong.school |
| CVE-2026-64157 | netfs: Fix partial invalidation of streaming-write folio | HalfBakedFolio | https://halfbakedfolio.pizza |
| CVE-2026-64156 | netfs, afs: Fix write skipping in dir/link writepages | SkippedWriteDay | https://skippedwriteday.fit |
| CVE-2026-64155 | wifi: ath11k: fix error path leaks in some WMI WOW calls | WorldOfLeakcraft | https://worldofleakcraft.gg |
| CVE-2026-64154 | drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() | AdrenalineLeak | https://adrenalineleak.energy |
| CVE-2026-64153 | drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN | SGTableFlip | https://sgtableflip.rocks |
| CVE-2026-64126 | Bluetooth: MGMT: validate Add Extended Advertising Data length | TruthInAdvertising | https://truthinadvertising.biz |
| CVE-2026-64152 | iommu: Handle unmap error when iommu_debug is enabled | UnmapQuest | https://unmapquest.lol |
| CVE-2026-64151 | iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap | OneSizeFitsNone | https://onesizefitsnone.fit |
| CVE-2026-64150 | netfilter: nft_inner: release local_lock before re-enabling softirqs | InnerTurmoil | https://innerturmoil.art |
| CVE-2026-64149 | dma-mapping: move dma_map_resource() sanity check into debug code | SanityOptional | https://sanityoptional.wtf |
| CVE-2026-64148 | pds_core: fix error handling in pdsc_devcmd_wait | CmdAndConquer | https://cmdandconquer.io |
| CVE-2026-64147 | pds_core: fix debugfs_lookup dentry leak and error handling | DentryPlan | https://dentryplan.dental |
| CVE-2026-64146 | erofs: fix metabuf leak in inode xattr initialization | MetaBuffet | https://metabuffet.cafe |
| CVE-2026-64145 | wifi: wilc1000: fix dma_buffer leak on bus acquire failure | UnderTheBus | https://underthebus.taxi |
| CVE-2026-64144 | Bluetooth: btmtk: fix urb->setup_packet leak in error paths | URBanLegend | https://urbanlegend.fm |
| CVE-2026-64143 | platform/x86: uniwill-laptop: Do not enable the charging limit even when forced | FullChargeAhead | https://fullchargeahead.energy |
| CVE-2026-64125 | net: bcmgenet: keep RBUF EEE/PM disabled | EEEGads | https://eeegads.lol |
| CVE-2026-64142 | ksmbd: close durable scavenger races against m_fp_list lookups | ScavengerHunt | https://scavengerhunt.party |
| CVE-2026-64141 | ksmbd: fix null pointer dereference in compare_guid_key() | MisGUIDed | https://misguided.rip |
| CVE-2026-64140 | ksmbd: fix null pointer dereference in proc_show_files() | NothingToShow | https://nothingtoshow.tv |
| CVE-2026-64139 | ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow | SIDShowBob | https://sidshowbob.tv |
| CVE-2026-64138 | ksmbd: validate SID in parent security descriptor during ACL inheritance | InheritanceScam | https://inheritancescam.money |
| CVE-2026-64137 | smb: client: require net admin for CIFS SWN netlink | SwornWitness | https://swornwitness.lawyer |
| CVE-2026-64136 | smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() | TconArtist | https://tconartist.biz |
| CVE-2026-64135 | hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX | BlackBoxBlues | https://blackboxblues.fm |
| CVE-2026-64134 | ALSA: pcm: Don't setup bogus iov_iter for silencing | SoundOfSilence | https://soundofsilence.audio |
| CVE-2026-64133 | ALSA: asihpi: Fix potential OOB array access at reading cache | CacheTwentyTwo | https://cachetwentytwo.aero |
| CVE-2026-64124 | net: devmem: reject dma-buf bind with non-page-aligned size or SG length | ChaoticMisaligned | https://chaoticmisaligned.games |
| CVE-2026-64084 | hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR | PDIOverboard | https://pdioverboard.cruises |
| CVE-2026-64093 | batman-adv: tp_meter: directly shut down timer on cleanup | SameBatTime | https://samebattime.day |
| CVE-2026-64092 | batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown | BatSignalLeak | https://batsignalleak.news |
| CVE-2026-64091 | batman-adv: tt: fix TOCTOU race for reported vlans | VLANdalism | https://vlandalism.art |
| CVE-2026-64090 | batman-adv: tt: avoid empty VLAN responses | VLANishingAct | https://vlanishingact.show |
| CVE-2026-64089 | batman-adv: tt: fix negative last_changeset_len | ChangesetOfHeart | https://changesetofheart.chat |
| CVE-2026-64088 | batman-adv: tt: fix negative tt_buff_len | NegativeBuff | https://negativebuff.gg |
| CVE-2026-64122 | net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover | GhostReporter | https://ghostreporter.news |
| CVE-2026-64121 | net: ifb: report ethtool stats over num_tx_queues | StatPadding | https://statpadding.fit |
| CVE-2026-64120 | net: ethtool: fix NULL pointer dereference in phy_reply_size | PHYnalAnswer | https://phynalanswer.money |
| CVE-2026-64119 | l2tp: use list_del_rcu in l2tp_session_unhash | UnhashBrowns | https://unhashbrowns.kitchen |
| CVE-2026-64118 | qed: fix double free in qed_cxt_tables_alloc() | DoubleFreeDiscount | https://doublefreediscount.deals |
| CVE-2026-64117 | wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb | MeshedUp | https://meshedup.wtf |
| CVE-2026-64116 | ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() | HopSkipCrash | https://hopskipcrash.horse |
| CVE-2026-64115 | vsock/vmci: fix UAF when peer resets connection during handshake | HandshakeAndBake | https://handshakeandbake.pizza |
| CVE-2026-64114 | ipv4: raw: reject IP_HDRINCL packets with ihl < 5 | ShrunkenHeader | https://shrunkenheader.clothing |
| CVE-2026-64087 | hwmon: (pmbus/adm1266) reject implausible blackbox record_count | RecordScratch | https://recordscratch.dj |
| CVE-2026-64113 | ixgbevf: fix use-after-free in VEPA multicast source pruning | PrunedToDeath | https://prunedtodeath.garden |
| CVE-2026-64112 | rbd: eliminate a race in lock_dwork draining on unmap | DrainedAndConfused | https://drainedandconfused.plumbing |
| CVE-2026-64111 | lsm: hold cred_guard_mutex for lsm_set_self_attr() | SelfAttrEsteem | https://selfattresteem.chat |
| CVE-2026-64110 | igc: fix potential skb leak in igc_fpe_xmit_smd_frame() | FramedAndLeaked | https://framedandleaked.art |
| CVE-2026-64109 | af_unix: Fix UAF read of tail->len in unix_stream_data_wait() | TailRisk | https://tailrisk.money |
| CVE-2026-64108 | cifs: Fix busy dentry used after unmounting | SquattersRights | https://squattersrights.estate |
| CVE-2026-64107 | ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put() | OverclockAndDagger | https://overclockanddagger.dj |
| CVE-2026-64106 | KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits | EventIDHorizon | https://eventidhorizon.events |
| CVE-2026-64105 | KVM: arm64: vgic: Free private_irqs when init fails after allocation | PrivateIRQuiry | https://privateirquiry.agency |
| CVE-2026-64104 | virt: sev-guest: Explicitly leak pages in unknown state | UnknownUnknowns | https://unknownunknowns.vote |
| CVE-2026-64086 | hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer | PECSAppeal | https://pecsappeal.fit |
| CVE-2026-64103 | scsi: isci: Fix use-after-free in device removal path | EvictionNotice | https://evictionnotice.rent |
| CVE-2026-64102 | RDMA/siw: Reject MPA FPDU length underflow before signed receive math | NegativeReception | https://negativereception.reviews |
| CVE-2026-64101 | fwctl: pds: Validate RPC input size before parsing | SightUnseen | https://sightunseen.auction |
| CVE-2026-64100 | drm/msm: Fix shrinker deadlock | ShrinkStalemate | https://shrinkstalemate.care |
| CVE-2026-64099 | drm/v3d: Fix use-after-free of CPU job query arrays on error path | QueriousGeorge | https://queriousgeorge.tv |
| CVE-2026-64098 | drm/virtio: use uninterruptible resv lock for plane updates | PlaneLocked | https://planelocked.aero |
| CVE-2026-64097 | drm/amd/display: Validate GPIO pin LUT table size before iterating | LUTOfTrouble | https://lutoftrouble.lol |
| CVE-2026-64096 | batman-adv: mcast: fix use-after-free in orig_node RCU release | OriginStory | https://originstory.film |
| CVE-2026-64095 | batman-adv: bla: avoid double decrement of bla.num_requests | DecrementalHealth | https://decrementalhealth.clinic |
| CVE-2026-64094 | batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface | ClaimDenied | https://claimdenied.claims |
| CVE-2026-64085 | hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer | BlackboxBouncer | https://blackboxbouncer.club |
| CVE-2026-64045 | ovpn: tcp - use cached peer pointer in ovpn_tcp_close() | PeerPressure | https://peerpressure.school |
| CVE-2026-64054 | net: shaper: reject duplicate leaves in GROUP request | LeafMeAlone | https://leafmealone.garden |
| CVE-2026-64053 | block: don't overwrite bip_vcnt in bio_integrity_copy_user() | CheckBounced | https://checkbounced.cash |
| CVE-2026-64052 | block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() | ZeroIntegrity | https://zerointegrity.vote |
| CVE-2026-64051 | accel/qaic: Add overflow check to remap_pfn_range during mmap | RemapRodeo | https://remaprodeo.horse |
| CVE-2026-64050 | drm/msm/dpu: don't mix devm and drmm functions | DevmMayCare | https://devmmaycare.wtf |
| CVE-2026-64049 | drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx | AdrenoLine | https://adrenoline.energy |
| CVE-2026-64083 | hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors | ShortBus | https://shortbus.fail |
| CVE-2026-64082 | riscv: Fix register corruption from uninitialized cregs on error | CregsList | https://cregslist.biz |
| CVE-2026-64081 | firmware: arm_ffa: Validate framework notification message layout | FFAkeNews | https://ffakenews.news |
| CVE-2026-64080 | firmware: arm_ffa: Snapshot notifier callbacks under lock | SnapJudgment | https://snapjudgment.photos |
| CVE-2026-64079 | netfilter: x_tables: allocate hook ops while under mutex | HookedOnMutex | https://hookedonmutex.rocks |
| CVE-2026-64078 | netfilter: x_tables: add and use xtables_unregister_table_exit | TableFlip | https://tableflip.furniture |
| CVE-2026-64077 | netfilter: ebtables: move to two-stage removal scheme | DoubleTakedown | https://doubletakedown.lawyer |
| CVE-2026-64076 | netfilter: bridge: eb_tables: close module init race | BridgeTooFast | https://bridgetoofast.horse |
| CVE-2026-64075 | fprobe: Fix unregister_fprobe() to wait for RCU grace period | GracelessExit | https://gracelessexit.day |
| CVE-2026-64048 | net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot | EmptySlotMachine | https://emptyslotmachine.money |
| CVE-2026-64074 | fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap | SlabAvalanche | https://slabavalanche.rocks |
| CVE-2026-64073 | irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT | WorkAfterDeath | https://workafterdeath.rip |
| CVE-2026-64072 | nvme: fix bio leak on mapping failure | BioHazard | https://biohazard.zip |
| CVE-2026-64071 | nvme-pci: fix use-after-free in nvme_free_host_mem() | HostBusters | https://hostbusters.com |
| CVE-2026-64070 | powerpc/hv-gpci: fix preempt count leak in sysfs show paths | ShowStopper | https://showstopper.tv |
| CVE-2026-64069 | netfs: Fix cancellation of a DIO and single read subrequests | CancelCulture | https://cancelculture.wtf |
| CVE-2026-64068 | netfs: Fix missing locking around retry adding new subreqs | RetryHard | https://retryhard.io |
| CVE-2026-64067 | netfs: Fix missing barriers when accessing stream->subrequests locklessly | BarrierReef | https://barrierreef.stream |
| CVE-2026-64066 | netfs: Fix netfs_read_to_pagecache() to pause on subreq failure | PauseForConcern | https://pauseforconcern.media |
| CVE-2026-64065 | netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call | PortfolioBug | https://portfoliobug.art |
| CVE-2026-64047 | net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring | OneLinkShort | https://onelinkshort.link |
| CVE-2026-64064 | netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone | DirtyLaundry | https://dirtylaundry.exposed |
| CVE-2026-64063 | netfs: Fix streaming write being overwritten | StreamSniped | https://streamsniped.stream |
| CVE-2026-64062 | netfs: Fix potential deadlock in write-through mode | WriteOfTheDead | https://writeofthedead.zone |
| CVE-2026-64061 | netfs: Fix early put of sink folio in netfs_read_gaps() | SinkingFeeling | https://sinkingfeeling.fail |
| CVE-2026-64060 | netfs: Fix leak of request in netfs_write_begin() error handling | LeakyBeginnings | https://leakybeginnings.plumbing |
| CVE-2026-64059 | netfs: Fix folio->private handling in netfs_perform_write() | PrivateParts | https://privateparts.exposed |
| CVE-2026-64058 | netfs: Fix netfs_read_folio() to wait on writeback | WaitWatchers | https://waitwatchers.fit |
| CVE-2026-64057 | afs: Fix the locking used by afs_get_link() | WeakestLink | https://weakestlink.tv |
| CVE-2026-64056 | net: ethernet: cortina: Make RX SKB per-port | AnyPortInAStorm | https://anyportinastorm.surf |
| CVE-2026-64055 | net: ethernet: cortina: Carry over frag counter | CarryOnFragging | https://carryonfragging.gg |
| CVE-2026-64046 | net: tls: prevent chain-after-chain in plain text SG | ChainSmoker | https://chainsmoker.dj |
| CVE-2026-64015 | security/keys: fix missed RCU read section on lookup | KeylessEntry | https://keylessentry.estate |
| CVE-2026-64024 | tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction | ISNstradamus | https://isnstradamus.biz |
| CVE-2026-64023 | gpio: aggregator: fix a potential use-after-free | AggroGate | https://aggrogate.io |
| CVE-2026-64022 | gpio: aggregator: remove the software node when deactivating the aggregator | GhostNode | https://ghostnode.cloud |
| CVE-2026-64021 | drm/xe/oa: Fix exec_queue leak on width check in stream open | QueueTips | https://queuetips.dev |
| CVE-2026-64020 | nvme-pci: fix dma_vecs leak on p2p memory | PeerReviewFailed | https://peerreviewfailed.science |
| CVE-2026-64019 | nvme-pci: fix dma mapping leak on data setup error | MapLeaks | https://mapleaks.news |
| CVE-2026-64018 | net: mana: validate rx_req_idx to prevent out-of-bounds array access | ManaOverflow | https://manaoverflow.gg |
| CVE-2026-64044 | ovpn: respect peer refcount in CMD_NEW_PEER error path | PeerReview | https://peerreview.science |
| CVE-2026-64043 | ovpn: fix race between deleting interface and adding new peer | DisapPeered | https://disappeered.io |
| CVE-2026-64042 | vfio/pci: Check BAR resources before exporting a DMABUF | BARFight | https://barfight.lol |
| CVE-2026-64041 | ASoC: codecs: fs210x: fix possible buffer overflow | CodecBlue | https://codecblue.audio |
| CVE-2026-64040 | cachefiles: Fix error return when vfs_mkdir() fails | MkdirtyDeeds | https://mkdirtydeeds.cheap |
| CVE-2026-64039 | drm/msm/snapshot: fix dumping of the unaligned regions | DumpAndDumper | https://dumpanddumper.film |
| CVE-2026-64038 | hwmon: (lm90) Stop work before releasing hwmon device | CantStopWontStop | https://cantstopwontstop.work |
| CVE-2026-64037 | wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled | GeneralTSO | https://generaltso.pizza |
| CVE-2026-64036 | cgroup/rstat: validate cpu before css_rstat_cpu() access | OffTheCharts | https://offthecharts.top |
| CVE-2026-64035 | igc: set tx buffer type for SMD frames | FrameJob | https://framejob.art |
| CVE-2026-64017 | blk-mq: pop cached request if it is usable | PopGoesTheRequest | https://popgoestherequest.lol |
| CVE-2026-64034 | net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer | FetchHappens | https://fetchhappens.dog |
| CVE-2026-64033 | RDMA/rtrs: Fix use-after-free in path file creation cleanup | PathoLogical | https://pathological.direct |
| CVE-2026-64032 | bridge: mcast: Fix a possible use-after-free when removing a bridge port | BurnedBridges | https://burnedbridges.estate |
| CVE-2026-64031 | erofs: fix managed cache race for unaligned extents | ExtentOfTheDamage | https://extentofthedamage.lawyer |
| CVE-2026-64030 | wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs | LinkedOut | https://linkedout.biz |
| CVE-2026-64029 | ALSA: seq: Serialize UMP output teardown with event_input | UMPlugged | https://umplugged.audio |
| CVE-2026-64028 | tracing: Avoid NULL return from hist_field_name() on truncation | TruncatedHistory | https://truncatedhistory.news |
| CVE-2026-64027 | net: shaper: rework the VALID marking (again) | ShapeShifter | https://shapeshifter.fit |
| CVE-2026-64026 | rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg | SpliceGirls | https://splicegirls.fm |
| CVE-2026-64025 | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx | RushedVerdict | https://rushedverdict.lawyer |
| CVE-2026-64016 | ksmbd: fix durable reconnect error path file lifetime | ReconnectFour | https://reconnectfour.party |
| CVE-2026-63989 | bridge: Fix sleep in atomic context in netlink path | AtomicNap | https://atomicnap.energy |
| CVE-2026-63998 | ethtool: module: call ethnl_ops_complete() on module flash errors | UnfinishedBusiness | https://unfinishedbusiness.biz |
| CVE-2026-63997 | ethtool: module: avoid leaking a netdev ref on module flash errors | RefMadness | https://refmadness.film |
| CVE-2026-63996 | ethtool: cmis: require exact CDB reply length | CurtReply | https://curtreply.chat |
| CVE-2026-63995 | ethtool: cmis: validate start_cmd_payload_size from module | PayloadedQuestion | https://payloadedquestion.lol |
| CVE-2026-63994 | tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() | CowTipping | https://cowtipping.farm |
| CVE-2026-63993 | vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() | StaleMate | https://stalemate.day |
| CVE-2026-63992 | tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() | TunnelVision | https://tunnelvision.tv |
| CVE-2026-64014 | Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size | OutOfTouch | https://outoftouch.fm |
| CVE-2026-64013 | ACPI: button: Fix ACPI GPE handler leak during removal | ButtonMasher | https://buttonmasher.gg |
| CVE-2026-64012 | net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked | PeekPerformance | https://peekperformance.fit |
| CVE-2026-64011 | nfc: llcp: Fix use-after-free in llcp_sock_release() | TapAndDie | https://tapanddie.money |
| CVE-2026-64010 | nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() | CCYouLater | https://ccyoulater.chat |
| CVE-2026-64009 | xfrm: Check for underflow in xfrm_state_mtu | MTUnderflow | https://mtunderflow.zip |
| CVE-2026-63991 | Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() | SendInTheClones | https://sendintheclones.army |
| CVE-2026-64008 | accel/rocket: fix UAF via dangling GEM handle in create_bo | DanglingGEM | https://danglinggem.rocks |
| CVE-2026-64007 | netfilter: synproxy: refresh tcphdr after skb_ensure_writable | SynfulProxy | https://synfulproxy.church |
| CVE-2026-64006 | netfilter: nf_tables: fix dst corruption in same register operation | CorruptRegister | https://corruptregister.vote |
| CVE-2026-64005 | net/smc: Do not re-initialize smc hashtables | ReHashed | https://rehashed.kitchen |
| CVE-2026-64004 | net/iucv: fix locking in .getsockopt | SockOptOut | https://sockoptout.us |
| CVE-2026-64003 | scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues | QueueJumper | https://queuejumper.horse |
| CVE-2026-64002 | ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() | UnreservedSeating | https://unreservedseating.aero |
| CVE-2026-64001 | ALSA: pcm: oss: Fix setup list UAF on proc write error | OSSuary | https://ossuary.rip |
| CVE-2026-64000 | net: hsr: fix potential OOB access in supervision frame handling | UnsupervisedLearning | https://unsupervisedlearning.academy |
| CVE-2026-63999 | ethtool: rss: fix indir_table and hkey leak on get_rxfh failure | HashSlingingLeaker | https://hashslingingleaker.restaurant |
| CVE-2026-63990 | bonding: refuse to enslave CAN devices | CANtTouchThis | https://canttouchthis.dance |
| CVE-2026-63947 | Bluetooth: HIDP: fix missing length checks in hidp_input_report() | HIDPandSeek | https://hidpandseek.games |
| CVE-2026-63956 | USB: serial: cypress_m8: fix memory corruption with small endpoint | CypressHill | https://cypresshill.dj |
| CVE-2026-63955 | mm/vmalloc: do not trigger BUG() on BH disabled context | BottomHalfEmpty | https://bottomhalfempty.bar |
| CVE-2026-63954 | hpfs: fix a crash if hpfs_map_dnode_bitmap fails | BitmapOfNowhere | https://bitmapofnowhere.travel |
| CVE-2026-63953 | mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page | MigratoryLeak | https://migratoryleak.aero |
| CVE-2026-63952 | memfd: deny writeable mappings when implying SEAL_WRITE | SealOfDisapproval | https://sealofdisapproval.vote |
| CVE-2026-63988 | bridge: Fix sleep in atomic context in sysfs path | AtomicSnooze | https://atomicsnooze.day |
| CVE-2026-63987 | ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES | DIMWitted | https://dimwitted.wtf |
| CVE-2026-63951 | zram: fix use-after-free in zram_writeback_endio | ZombieRAM | https://zombieram.rip |
| CVE-2026-63986 | ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure | ErrPointerSisters | https://errpointersisters.band |
| CVE-2026-63985 | ethtool: eeprom: add more safeties to EEPROM Netlink fallback | FallbackBoy | https://fallbackboy.fm |
| CVE-2026-63984 | ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() | DecompressionSickness | https://decompressionsickness.zip |
| CVE-2026-63983 | net/sched: fix packet loop on netem when duplicate is on | LoopDreams | https://loopdreams.film |
| CVE-2026-63982 | net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop | MirredImage | https://mirredimage.art |
| CVE-2026-63981 | net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow | RecursionExcursion | https://recursionexcursion.travel |
| CVE-2026-63980 | net/handshake: Use spin_lock_bh for hn_lock | SecretHandshake | https://secrethandshake.club |
| CVE-2026-63979 | net/handshake: hand off the pinned file reference to accept_doit | HandMeDown | https://handmedown.fashion |
| CVE-2026-63978 | net/handshake: Drain pending requests at net namespace exit | LeftHanging | https://lefthanging.fail |
| CVE-2026-63977 | dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work | SpareChange | https://sparechange.money |
| CVE-2026-63950 | mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one | OneMapWonder | https://onemapwonder.page |
| CVE-2026-63976 | Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success | EcredScore | https://ecredscore.money |
| CVE-2026-63975 | Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp | EcredCrunch | https://ecredcrunch.fail |
| CVE-2026-63974 | Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close | DrainedTooth | https://drainedtooth.dental |
| CVE-2026-63973 | net: mana: Add NULL guards in teardown path to prevent panic on attach failure | OutOfMana | https://outofmana.gg |
| CVE-2026-63972 | net: mana: Skip redundant detach on already-detached port | DetachedMana | https://detachedmana.lol |
| CVE-2026-63971 | sctp: fix race between sctp_wait_for_connect and peeloff | SlipperyPeel | https://slipperypeel.fail |
| CVE-2026-63970 | vsock/virtio: bind uarg before filling zerocopy skb | ZeroCopyCat | https://zerocopycat.cat |
| CVE-2026-63969 | ipv6: fix possible infinite loop in rt6_fill_node() | RouteSixtyLoop | https://routesixtyloop.us |
| CVE-2026-63968 | ipv6: fix possible infinite loop in fib6_select_path() | EndlessFib | https://endlessfib.news |
| CVE-2026-63967 | iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer | FifoLeaks | https://fifoleaks.news |
| CVE-2026-63949 | auxdisplay: line-display: fix OOB read on zero-length message_store() | BetweenTheLines | https://betweenthelines.art |
| CVE-2026-63966 | iio: imu: adis16550: fix stack leak in trigger handler | TriggerHappy | https://triggerhappy.io |
| CVE-2026-63965 | iio: pressure: bmp280: fix stack leak in bmp580 trigger handler | UnderPressure | https://underpressure.fm |
| CVE-2026-63964 | usb: typec: ucsi: ccg: reject firmware images without a ':' record header | MissingColon | https://missingcolon.wtf |
| CVE-2026-63963 | usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers | IdentityTheft | https://identitytheft.money |
| CVE-2026-63962 | usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() | ModeBuffet | https://modebuffet.pizza |
| CVE-2026-63961 | usb: typec: altmodes/displayport: validate count before reading Status Update VDO | StatusAnxiety | https://statusanxiety.chat |
| CVE-2026-63960 | usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() | SmugglersCove | https://smugglerscove.rocks |
| CVE-2026-63959 | usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT | MaximOverdrive | https://maximoverdrive.film |
| CVE-2026-63958 | usb: typec: ucsi: validate connector number in ucsi_connector_change() | ConnectorFour | https://connectorfour.gg |
| CVE-2026-63957 | USB: serial: safe_serial: fix memory corruption with small endpoint | NotSoSafeSerial | https://notsosafeserial.fail |
| CVE-2026-63948 | Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn | LeakyChannel | https://leakychannel.tv |
| CVE-2026-63906 | usb: musb: omap2430: Fix use-after-free in omap2430_probe() | MusbBeFree | https://musbbefree.lol |
| CVE-2026-63915 | nfc: hci: fix out-of-bounds read in HCP header parsing | OutOfHeaders | https://outofheaders.news |
| CVE-2026-63914 | xfrm: route MIGRATE notifications to caller's netns | MigrationSeason | https://migrationseason.aero |
| CVE-2026-63913 | netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check | RstInPeace | https://rstinpeace.rip |
| CVE-2026-63912 | xfrm: esp: restore combined single-frag length gate | FragGate | https://fraggate.news |
| CVE-2026-63911 | xfrm: iptfs: reset runtime state when cloning SAs | AttackOfTheClones | https://attackoftheclones.movie |
| CVE-2026-63946 | Bluetooth: ISO: fix UAF in iso_recv_frame | FreezeFrame | https://freezeframe.fm |
| CVE-2026-63910 | dma-buf: fix UAF in dma_buf_fd() tracepoint | TracePointBlank | https://tracepointblank.wtf |
| CVE-2026-63945 | Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock | IsoOutOfSync | https://isooutofsync.day |
| CVE-2026-63944 | Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync | SyncOrSwim | https://syncorswim.fail |
| CVE-2026-63943 | Input: xpad - fix out-of-bounds access for Share button | OverShare | https://overshare.lol |
| CVE-2026-63942 | parport: Fix race between port and client registration | ParallelParking | https://parallelparking.fail |
| CVE-2026-63941 | KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor | VectorVictor | https://vectorvictor.aero |
| CVE-2026-63940 | KVM: SEV: Ignore Port I/O requests of length '0' | MuchAdoAboutZero | https://muchadoaboutzero.art |
| CVE-2026-63939 | KVM: SEV: Compute the correct max length of the in-GHCB scratch area | ScratchThat | https://scratchthat.dj |
| CVE-2026-63938 | KVM: SEV: Check PSC request indices against the actual size of the buffer | IndexFund | https://indexfund.money |
| CVE-2026-63937 | KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer | ReadOnceLiveTwice | https://readoncelivetwice.film |
| CVE-2026-63936 | iio: adc: mt6359: fix unchecked return value in mt6358_read_imp | UncheckedBaggage | https://uncheckedbaggage.aero |
| CVE-2026-63909 | ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops | AceVenturer | https://aceventurer.dog |
| CVE-2026-63935 | iio: adc: nxp-sar-adc: fix division by zero in write_raw | DivisionByZorro | https://divisionbyzorro.horse |
| CVE-2026-63934 | iio: gyro: itg3200: fix i2c read into the wrong stack location | MisplacedGyro | https://misplacedgyro.pizza |
| CVE-2026-63933 | iio: gyro: adis16260: fix division by zero in write_raw | ZeroSpin | https://zerospin.fit |
| CVE-2026-63932 | iio: chemical: mhz19b: reject oversized serial replies | CarbonOverload | https://carbonoverload.energy |
| CVE-2026-63931 | iio: chemical: scd30: fix division by zero in write_raw | NetZeroDivision | https://netzerodivision.vote |
| CVE-2026-63930 | iio: buffer: hw-consumer: fix use-after-free in error path | ConsumerRegret | https://consumerregret.money |
| CVE-2026-63929 | iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() | LeakyFence | https://leakyfence.estate |
| CVE-2026-63928 | USB: serial: omninet: fix memory corruption with small endpoint | OmniShambles | https://omnishambles.wtf |
| CVE-2026-63927 | usb: dwc2: Fix use after free in debug code | PostMortemDebug | https://postmortemdebug.rip |
| CVE-2026-63926 | bpf: sockmap: fix tail fragment offset in bpf_msg_push_data | PushItRealBad | https://pushitrealbad.fm |
| CVE-2026-63908 | Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem | TouchAndGo | https://touchandgo.aero |
| CVE-2026-63925 | macsec: fix replay protection at XPN lower-PN wrap | ReplayItAgainSam | https://replayitagainsam.film |
| CVE-2026-63924 | ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() | JumboHopscotch | https://jumbohopscotch.scot |
| CVE-2026-63923 | octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify | BodySnatchers | https://bodysnatchers.film |
| CVE-2026-63922 | ipv6: exthdrs: refresh nh after handling HAO option | HaoNowBrownCow | https://haonowbrowncow.lol |
| CVE-2026-63921 | ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). | CarpalTunnel | https://carpaltunnel.health |
| CVE-2026-63920 | ipv6: validate extension header length before copying to cmsg | HeadOverHeels | https://headoverheels.fm |
| CVE-2026-63919 | xfrm: input: hold netns during deferred transport reinjection | BoosterShot | https://boostershot.fit |
| CVE-2026-63918 | l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname | ZeroRefsGiven | https://zerorefsgiven.wtf |
| CVE-2026-63917 | ip6: vti: Use ip6_tnl.net in vti6_changelink(). | WrongWayTunnel | https://wrongwaytunnel.us |
| CVE-2026-63916 | HID: wacom: Fix OOB write in wacom_hid_set_device_mode() | OutsideTheLines | https://outsidethelines.art |
| CVE-2026-63907 | uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory | BuyOneGetOneFree | https://buyonegetonefree.money |
| CVE-2026-63875 | arm64: tlb: Flush walk cache when unsharing PMD tables | CourtesyFlush | https://courtesyflush.fail |
| CVE-2026-63884 | drm/i915: Fix potential UAF in TTM object purge | PurgeAfterReading | https://purgeafterreading.film |
| CVE-2026-63883 | serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ | GeniInABottle | https://geniinabottle.fm |
| CVE-2026-63882 | drm/amdkfd: fix NULL pointer bug in svm_range_set_attr | FreeRangeNull | https://freerangenull.horse |
| CVE-2026-63881 | drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger | DebuggerOverboard | https://debuggeroverboard.film |
| CVE-2026-63880 | drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO | LockedOutOfMemory | https://lockedoutofmemory.fail |
| CVE-2026-63879 | drm/amdgpu: fix amdgpu_hmm_range_get_pages | HmmThatsOdd | https://hmmthatsodd.wtf |
| CVE-2026-63905 | usbip: vudc: Fix use after free bug in vudc_remove due to race condition | VirtualInsanity | https://virtualinsanity.fm |
| CVE-2026-63878 | drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO | UncountedGems | https://uncountedgems.money |
| CVE-2026-63904 | usb: usbtmc: check URB actual_length for interrupt-IN notifications | ActualSizeMayVary | https://actualsizemayvary.lol |
| CVE-2026-63903 | USB: serial: belkin_sa: validate interrupt status length | ShortStatus | https://shortstatus.chat |
| CVE-2026-63902 | USB: serial: cypress_m8: validate interrupt packet headers | CypressSpill | https://cypressspill.fm |
| CVE-2026-63901 | USB: serial: digi_acceleport: fix memory corruption with small endpoints | SpeedBump | https://speedbump.fail |
| CVE-2026-63900 | USB: serial: keyspan: fix missing indat transfer sanity check | KeyspanInsanity | https://keyspaninsanity.wtf |
| CVE-2026-63899 | USB: serial: mxuport: fix memory corruption with small endpoint | PointOfNoReturn | https://pointofnoreturn.fm |
| CVE-2026-63898 | USB: serial: mct_u232: fix memory corruption with small endpoint | UBoat232 | https://uboat232.rip |
| CVE-2026-63897 | USB: serial: mct_u232: fix missing interrupt-in transfer sanity check | PeriscopeDown | https://periscopedown.fail |
| CVE-2026-63896 | usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling | SixFeetUnderflow | https://sixfeetunderflow.rip |
| CVE-2026-63895 | usb: gadget: f_fs: copy only received bytes on short ep0 read | ShortChanged | https://shortchanged.money |
| CVE-2026-63877 | serial: dz: Convert to use a platform device | DzNuts | https://dznuts.lol |
| CVE-2026-63894 | usb: gadget: f_fs: serialize DMABUF cancel against request completion | Uncancellable | https://uncancellable.wtf |
| CVE-2026-63893 | thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() | ThunderWrap | https://thunderwrap.pizza |
| CVE-2026-63892 | thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow | ThunderFromDownUnder | https://thunderfromdownunder.fm |
| CVE-2026-63891 | thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() | RecursionConcussion | https://recursionconcussion.io |
| CVE-2026-63890 | scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker | FipFlop | https://fipflop.fail |
| CVE-2026-63889 | scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 | NarrowMinded | https://narrowminded.wtf |
| CVE-2026-63888 | scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() | CrcAndBurn | https://crcandburn.fail |
| CVE-2026-63887 | scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf | RunOnSentence | https://runonsentence.chat |
| CVE-2026-63886 | scsi: target: iscsi: Validate CHAP_R length before base64 decode | ChapStick | https://chapstick.lol |
| CVE-2026-63885 | drm/gem: fix race between change_handle and handle_delete | HandleWithoutCare | https://handlewithoutcare.fm |
| CVE-2026-63876 | serial: zs: Convert to use a platform device | CatchingZs | https://catchingzs.day |
| CVE-2026-63874 | net: mctp: usb: fix race between urb completion and rx_retry cancellation | TryTryRaceAgain | https://trytryraceagain.horse |
| CVE-2026-63872 | esp: fix page frag reference leak on skb_to_sgvec failure | EauDeFrag | https://eaudefrag.lol |
| CVE-2026-63873 | accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range() | StructuralLeakage | https://structuralleakage.estate |
| CVE-2026-63870 | ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() | StickyPan | https://stickypan.pizza |
| CVE-2026-63871 | Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls | RouteRage | https://routerage.wtf |
| CVE-2026-63869 | wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap | AntennaGate | https://antennagate.news |
| CVE-2026-63867 | mptcp: close TOCTOU race while computing rcv_wnd | WindowShopping | https://windowshopping.money |
| CVE-2026-63868 | net: garp: fix unsigned integer underflow in garp_pdu_parse_attr | AccordingToGarp | https://accordingtogarp.film |
| CVE-2026-63855 | drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings | NoFenceIntended | https://nofenceintended.lol |
| CVE-2026-63864 | bpf: Propagate error from visit_tailcall_insn | TailFail | https://tailfail.fail |
| CVE-2026-63863 | drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm() | UnLockness | https://unlockness.scot |
| CVE-2026-63862 | PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found | DomainSquatter | https://domainsquatter.biz |
| CVE-2026-63861 | spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback | EccentricEngine | https://eccentricengine.rocks |
| CVE-2026-63860 | RDMA/core: Prefer NLA_NUL_STRING | NulAndVoid | https://nulandvoid.lawyer |
| CVE-2026-63859 | net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue() | MissingBits | https://missingbits.stream |
| CVE-2026-63858 | netfilter: nf_tables: add hook transactions for device deletions | OffTheHook | https://offthehook.fish |
| CVE-2026-63857 | net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() | FragNarok | https://fragnarok.gg |
| CVE-2026-63866 | wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link() | WcidThisWay | https://wcidthisway.com |
| CVE-2026-63865 | bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks | SleeperHook | https://sleeperhook.rest |
| CVE-2026-63856 | drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings | PicketFence | https://picketfence.garden |
| CVE-2026-63846 | drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring | OnTheFence | https://onthefence.vote |
| CVE-2026-63845 | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring | DefencelessJpeg | https://defencelessjpeg.art |
| CVE-2026-63844 | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring | PicketFail | https://picketfail.fail |
| CVE-2026-63843 | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring | FenceHopper | https://fencehopper.horse |
| CVE-2026-63842 | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring | GoodFencesBadRings | https://goodfencesbadrings.estate |
| CVE-2026-63841 | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring | FenceSitter | https://fencesitter.fyi |
| CVE-2026-63840 | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring | MasterFencer | https://masterfencer.sport |
| CVE-2026-63839 | platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int() | LeakPad | https://leakpad.plumbing |
| CVE-2026-63854 | drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings | ElectricFence | https://electricfence.energy |
| CVE-2026-63853 | drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring | ChainLinked | https://chainlinked.money |
| CVE-2026-63852 | drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring | BarbedWired | https://barbedwired.band |
| CVE-2026-63851 | drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring | AmericanDreamFence | https://americandreamfence.us |
| CVE-2026-63850 | drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring | BeyondThePale | https://beyondthepale.beer |
| CVE-2026-63849 | drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring | UnFencedFrontier | https://unfencedfrontier.land |
| CVE-2026-63848 | drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring | DontFenceMeIn | https://dontfencemein.fm |
| CVE-2026-63847 | drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring | WhitewashedFence | https://whitewashedfence.page |
| CVE-2026-63837 | net: ena: PHC: Check return code before setting timestamp output | TimestampOfApproval | https://timestampofapproval.day |
| CVE-2026-63838 | ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] | DaiHard | https://daihard.audio |
| CVE-2026-63800 | pNFS: Fix use-after-free in pnfs_update_layout() | LayoutToRest | https://layouttorest.rip |
| CVE-2026-63809 | bpf: use kvfree() for replaced sysctl write buffer | MisFreesance | https://misfreesance.legal |
| CVE-2026-63808 | exfat: fix potential use-after-free in exfat_find_dir_entry() | GhostEntry | https://ghostentry.house |
| CVE-2026-63807 | KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level | HugeMistake | https://hugemistake.wtf |
| CVE-2026-63806 | KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() | BugOnArrival | https://bugonarrival.aero |
| CVE-2026-63805 | crypto: nx - fix nx_crypto_ctx_exit argument | PointlessArgument | https://pointlessargument.chat |
| CVE-2026-63804 | gfs2: fix use-after-free in gfs2_qd_dealloc | QuotaTheDay | https://quotatheday.today |
| CVE-2026-63836 | batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd | ZeroDarkThroughput | https://zerodarkthroughput.film |
| CVE-2026-63835 | batman-adv: v: prevent OGM aggregation on disabled hardif | GothamBroadcast | https://gothambroadcast.news |
| CVE-2026-63834 | batman-adv: tp_meter: restrict number of unacked list entries | AckHoarder | https://ackhoarder.storage |
| CVE-2026-63833 | ntfs3: reject direct userspace writes to reserved $LX* xattrs | ReservedNoMore | https://reservednomore.restaurant |
| CVE-2026-63832 | wifi: mt76: add wcid publish check in mt76_sta_add | PrematurePublication | https://prematurepublication.press |
| CVE-2026-63831 | mac802154: llsec: add skb_cow_data() before in-place crypto | HolyCowData | https://holycowdata.farm |
| CVE-2026-63830 | net: skmsg: preserve sg.copy across SG transforms | LostInTransform | https://lostintransform.tokyo |
| CVE-2026-63803 | hdlc_ppp: sync per-proto timers before freeing hdlc state | TimerAfterTime | https://timeraftertime.radio |
| CVE-2026-63829 | net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink | CapInHand | https://capinhand.cash |
| CVE-2026-63828 | apparmor: mediate the implicit connect of TCP fast open sendmsg | FastAndFurtive | https://fastandfurtive.racing |
| CVE-2026-63827 | apparmor: fix use-after-free in rawdata dedup loop | DedupOrAlive | https://deduporalive.dance |
| CVE-2026-63826 | fbdev: fix use-after-free in store_modes() | GhostOfModesPast | https://ghostofmodespast.christmas |
| CVE-2026-63825 | gcov: use atomic counter updates to fix concurrent access crashes | LosingCount | https://losingcount.accountant |
| CVE-2026-63824 | KEYS: fix overflow in keyctl_pkey_params_get_2() | OverKeyed | https://overkeyed.dj |
| CVE-2026-63823 | keys: Pin request_key_auth payload in instantiate paths | LostAuthority | https://lostauthority.city |
| CVE-2026-63822 | wifi: ath11k: fix warning when unbinding | UnbindingContract | https://unbindingcontract.ink |
| CVE-2026-63821 | wifi: rtw88: usb: fix memory leaks on USB write failures | ThumbDrip | https://thumbdrip.download |
| CVE-2026-63820 | f2fs: fix missing read bio submission on large folio error | UnsentBio | https://unsentbio.date |
| CVE-2026-63802 | blk-cgroup: fix UAF in __blkcg_rstat_flush() | RoyalFlushed | https://royalflushed.poker |
| CVE-2026-63819 | f2fs: fix to do sanity check on f2fs_get_node_folio_ra() | InsanityCheck | https://insanitycheck.clinic |
| CVE-2026-63818 | f2fs: validate orphan inode entry count | LittleOrphanInode | https://littleorphaninode.show |
| CVE-2026-63817 | f2fs: validate compress cache inode only when enabled | PhantomCompression | https://phantomcompression.zip |
| CVE-2026-63816 | f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode | AtomicWedgie | https://atomicwedgie.lol |
| CVE-2026-63815 | f2fs: bound i_inline_xattr_size for non-inline-xattr inodes | XattrLarge | https://xattrlarge.pizza |
| CVE-2026-63814 | f2fs: validate ACL entry sizes in f2fs_acl_from_disk() | TornAcl | https://tornacl.rehab |
| CVE-2026-63813 | Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block" | Revertigo | https://revertigo.film |
| CVE-2026-63812 | f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() | ExtentuatingCircumstances | https://extentuatingcircumstances.lawyer |
| CVE-2026-63811 | f2fs: read COW data with the original inode during atomic write | HolyCow | https://holycow.farm |
| CVE-2026-63810 | block: Avoid mounting the bdev pseudo-filesystem in userspace | PseudoMount | https://pseudomount.horse |
| CVE-2026-63801 | tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done | DecryptKeeper | https://decryptkeeper.rip |
| CVE-2026-53398 | NFSD: Fix SECINFO_NO_NAME decode error cleanup | NamelessDread | https://namelessdread.wtf |
| CVE-2026-53397 | nfsd: fix posix_acl leak on SETACL decode failure | AclInTheHole | https://aclinthehole.golf |
| CVE-2026-53396 | nfsd: fix posix_acl leak and ignored error in nfsd4_create_file | CreativeLeaking | https://creativeleaking.art |
| CVE-2026-53395 | nfsd: fix dead ACL conflict guard in nfsd4_create | SleepingGuard | https://sleepingguard.fail |
| CVE-2026-53394 | nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race | OwnerlessManor | https://ownerlessmanor.estate |
| CVE-2026-53393 | nfsd: reset write verifier on deferred writeback errors | TrustButVerifier | https://trustbutverifier.news |
| CVE-2026-53392 | NFSv4/flexfiles: reject zero filehandle version count | ZeroHandleGiven | https://zerohandlegiven.ninja |
| CVE-2026-63799 | sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path | ClearAndPresentDanger | https://clearandpresentdanger.film |
| CVE-2026-63798 | irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove | ChainOfFools | https://chainoffools.fm |
| CVE-2026-53391 | NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr | NoFixedAddress | https://nofixedaddress.estate |
| CVE-2026-63797 | rpmsg: char: Fix use-after-free on probe error path | DeadLetterOffice | https://deadletteroffice.email |
| CVE-2026-63796 | ocfs2: reject oversized group bitmap descriptors | ObeseBitmap | https://obesebitmap.fit |
| CVE-2026-63795 | 9p: avoid putting oldfid in p9_client_walk() error path | BadFido | https://badfido.dog |
| CVE-2026-63794 | KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path | CryptOverrun | https://cryptoverrun.money |
| CVE-2026-63793 | ntfs: serialize volume label accesses | OffLabel | https://offlabel.pharmacy |
| CVE-2026-53403 | fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var | ModelNoShow | https://modelnoshow.fashion |
| CVE-2026-53402 | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() | FontOfAllEvil | https://fontofallevil.art |
| CVE-2026-53401 | fbdev: omap2: fix use-after-free in omapfb_mmap | MmapFromTheGrave | https://mmapfromthegrave.rip |
| CVE-2026-53400 | i2c: core: fix adapter registration race | RegistrationDerby | https://registrationderby.bet |
| CVE-2026-53399 | nfsd: release layout stid on setlease failure | BrokenLease | https://brokenlease.rent |
| CVE-2026-53389 | net/tcp-ao: fix use-after-free of key in del_async path | SkeletonKey | https://skeletonkey.house |
| CVE-2026-53390 | ksmbd: fix out-of-bounds read in smb_check_perm_dacl() | DaclAndCover | https://daclandcover.us |
| CVE-2026-53388 | fuse: re-lock request before replacing page cache folio | ShortFuse | https://shortfuse.energy |
| CVE-2026-53387 | iio: light: veml6075: add bounds check to veml6075_it_ms index | SunburnIndex | https://sunburnindex.day |
| CVE-2026-53386 | iio: adc: ti-ads1298: add bounds check to pga_settings index | GainOfFunction | https://gainoffunction.bio |
| CVE-2026-53385 | vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write | ConsoleYourself | https://consoleyourself.chat |
| CVE-2026-53384 | serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails | PortOfNoReturn | https://portofnoreturn.cruises |
| CVE-2026-53383 | ksmbd: reject non-VALID session in compound request branch | SessionCrasher | https://sessioncrasher.party |
| CVE-2026-53381 | virtiofs: fix UAF on submount umount | SunkenSubmount | https://sunkensubmount.rocks |
| CVE-2026-53382 | media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si | DeadAir | https://deadair.tv |
| CVE-2026-53380 | media: rzv2h-ivc: Fix concurrent buffer list access | BufferingForever | https://bufferingforever.stream |
| CVE-2026-53379 | media: i2c: ov8856: free control handler on error in ov8856_init_controls() | OutOfControls | https://outofcontrols.camera |
| CVE-2026-53378 | drm/colorop: Fix blob property reference tracking in state lifecycle | ColorOutOfSpace | https://coloroutofspace.space |
| CVE-2026-53377 | drm/msm: always recover the gpu | LeftForDead | https://leftfordead.gg |
| CVE-2026-53376 | drm/amdkfd: Add upper bound check for num_of_nodes | NodeLimitHoldem | https://nodelimitholdem.casino |
| CVE-2026-53375 | drm/amdgpu/vce: Prevent partial address patches | PatchyAtBest | https://patchyatbest.reviews |
| CVE-2026-53373 | mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap() | PrematureUnmapping | https://prematureunmapping.travel |
| CVE-2026-53374 | drm/amdgpu: zero-initialize GART table on allocation | DirtyGarty | https://dirtygarty.party |
| CVE-2026-53372 | iommu/vt-d: Block PASID attachment to nested domain with dirty tracking | DirtyNest | https://dirtynest.homes |
| CVE-2026-53371 | RDMA/ionic: bound node_desc sysfs read with %.64s | DescGoneWild | https://descgonewild.tv |
| CVE-2026-53370 | perf/x86/intel: Improve validation and configuration of ACR masks | MaskOff | https://maskoff.club |
| CVE-2026-53369 | udf: reject descriptors with oversized CRC length | CrcYouLater | https://crcyoulater.surf |
| CVE-2026-53367 | selinux: fix avdcache auditing | CookingTheCache | https://cookingthecache.money |
| CVE-2026-53368 | f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage | FsckAroundFindOut | https://fsckaroundfindout.wtf |