Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51856
Total
4111
Critical
15381
High
15070
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63911 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: reset runtime state when cloning SAs iptfs_clone_state() clones the IPTFS mode data with … | Jul 19, 2026 |
| CVE-2026-63910 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dma-buf: fix UAF in dma_buf_fd() tracepoint Once FD_ADD() returns, the fd is live in the … | Jul 19, 2026 |
| CVE-2026-63909 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops Commit d07b26f39246 ("ksmbd: require minimum ACE size … | Jul 19, 2026 |
| CVE-2026-63908 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem When a configuration file provides an object … | Jul 19, 2026 |
| CVE-2026-63907 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory uio_pci_sva allocates struct uio_pci_sva_dev with devm_kzalloc() in … | Jul 19, 2026 |
| CVE-2026-63906 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: musb: omap2430: Fix use-after-free in omap2430_probe() In omap2430_probe(), of_node_put(np) is called prematurely before the … | Jul 19, 2026 |
| CVE-2026-63905 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usbip: vudc: Fix use after free bug in vudc_remove due to race condition This patch … | Jul 19, 2026 |
| CVE-2026-63904 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: check URB actual_length for interrupt-IN notifications USBTMC devices can use an optional interrupt … | Jul 19, 2026 |
| CVE-2026-63903 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: serial: belkin_sa: validate interrupt status length The Belkin interrupt callback treats interrupt data as … | Jul 19, 2026 |
| CVE-2026-63902 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: validate interrupt packet headers cypress_read_int_callback() parses the interrupt-in buffer according to the … | Jul 19, 2026 |
| CVE-2026-63901 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix memory corruption with small endpoints Add the missing bulk-out buffer size … | Jul 19, 2026 |
| CVE-2026-63900 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan: fix missing indat transfer sanity check Add the missing sanity check on … | Jul 19, 2026 |
| CVE-2026-63899 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: serial: mxuport: fix memory corruption with small endpoint Make sure that the bulk-out endpoint … | Jul 19, 2026 |
| CVE-2026-63898 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver overrides the maximum transfer … | Jul 19, 2026 |
| CVE-2026-63897 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix missing interrupt-in transfer sanity check Add the missing sanity check on … | Jul 19, 2026 |
| CVE-2026-63896 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling The WebUSB GET_URL handler in … | Jul 19, 2026 |
| CVE-2026-63895 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: copy only received bytes on short ep0 read ffs_ep0_read() allocates its control-OUT … | Jul 19, 2026 |
| CVE-2026-63894 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: serialize DMABUF cancel against request completion ffs_epfile_dmabuf_io_complete() calls usb_ep_free_request() on the completed … | Jul 19, 2026 |
| CVE-2026-63893 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the … | Jul 19, 2026 |
| CVE-2026-63892 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() … | Jul 19, 2026 |
| CVE-2026-63891 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() A DIRECTORY entry's value field is used as … | Jul 19, 2026 |
| CVE-2026-63890 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the descriptor … | Jul 19, 2026 |
| CVE-2026-63889 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 An adjacent Fibre Channel fabric actor … | Jul 19, 2026 |
| CVE-2026-63888 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the … | Jul 19, 2026 |
| CVE-2026-63887 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an … | Jul 19, 2026 |